Vulnerabilities and security researches forwp-smushit wp-smushit
Direction: ascendingJun 07, 2024
Smush – Optimize, Compress and Lazy Load Images # CVE-2017-15079
- CVE, Research URL
- Date
- Oct 06, 2017
- Research Description
- The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.
- Affected versions
-
max 2.7.6.
- Status
-
vulnerable
Smush – Optimize, Compress and Lazy Load Images # CVE-2022-1009
- CVE, Research URL
- Date
- May 30, 2022
- Research Description
- The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker would need an admin to upload a malicious configuration file
- Affected versions
-
max 3.9.9.
- Status
-
vulnerable
Jun 22, 2024
Smush – Optimize, Compress and Lazy Load Images # CVE-2023-3352
- CVE, Research URL
- Date
- Jun 21, 2024
- Research Description
- The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media Library.
- Affected versions
-
max 3.16.5.
- Status
-
vulnerable
Apr 02, 2025
Smush – Optimize, Compress and Lazy Load Images # CVE-2025-22288
- CVE, Research URL
- Date
- Nov 06, 2025
- Research Description
- Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0.
- Affected versions
-
max 3.17.1.
- Status
-
vulnerable
Jun 16, 2026
Smush – Optimize, Compress and Lazy Load Images # 41497e5826baf6a6bcedeca63643f2b334dba238
- CVE, Research URL
- Date
- Oct 09, 2017
- Research Description
- Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 2.7.6 WordPress Smush Image Compression and Optimization plugin <=2.7.5 - File Traversal vulnerability File Traversal vulnerability found by Ricardo Sánchez in WordPress Smush Image Compression and Optimization plugin (versions <=2.7.5).
- Affected versions
-
max 2.7.6.
- Status
-
vulnerable
Smush – Optimize, Compress and Lazy Load Images # 652cee930b4c5b4daf628ea8a9f3a802f0d99948
- CVE, Research URL
- Date
- Dec 10, 2018
- Research Description
- Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.0.0 WordPress Smush Image Compression and Optimization plugin <= 2.9.1 - Authenticated XSS & Phar Deserialization vulnerabilities Authenticated XSS & Phar Deserialization vulnerabilities found by RIPS Technologies in WordPress Smush Image Compression and Optimization plugin (versions <= 2.9.1).
- Affected versions
-
max 3.0.0.
- Status
-
vulnerable
Smush – Optimize, Compress and Lazy Load Images # 1b7b9063d6297ef0cf4d01b221d4e4da2c885eb9
- CVE, Research URL
- Date
- Dec 10, 2018
- Research Description
- Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.0.1 Smush – Lazy Load Images, Optimize & Compress Images <= 3.0.0 - Authenticated PHAR Deserialization The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 3.0.0. This makes it possible for authenticated attackers to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
- Affected versions
-
max 3.0.1.
- Status
-
vulnerable
Smush – Optimize, Compress and Lazy Load Images # a23c3a99b0a842dcbe6bec87be8b60c8ba8bf4da
- CVE, Research URL
- Date
- Dec 10, 2018
- Research Description
- Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.0.0 Smush – Lazy Load Images, Optimize & Compress Images <= 2.9.1 - Cross-Site Scripting The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Cross-Site Scripting leading in versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject malicious web scripts into the application.
- Affected versions
-
max 3.0.0.
- Status
-
vulnerable
Smush – Optimize, Compress and Lazy Load Images # b5bf5f41-aad3-45be-9cab-ab846b94003a
- CVE, Research URL
- Date
- -
- Research Description
- Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.9.9 Smush Image Compression and Optimization <= 2.9.1 - Authenticated Phar Deserialization The Smush – Lazy Load Images, Optimize & Compress Images WordPress plugin was affected by an Authenticated Phar Deserialization security vulnerability.
- Affected versions
-
max 3.9.9.
- Status
-
vulnerable
Jul 28, 2026
Smush – Optimize, Compress and Lazy Load Images # PSC-2026-64676
- PSC, Research URL
- Date
- Jul 28, 2026
- Research Description
- Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush - Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inputs, media permissions, generated formats, remote delivery settings, and public markup.
- Affected versions
-
Min 4.2.0, max 4.2.0.
- Status
-
SAFE & CERTIFIED