Shortpixel is an image-optimization vendor whose vulnerability profile concentrates in WordPress plugins such as Image Optimizer, Adaptive Images, and Enable Media Replace that extend media-handling capabilities for site builders. The recurring exposure centers on web-application access-control and input-handling weaknesses—including CSRF, improper authorization, path traversal, and cross-site scripting—that are characteristic of plugins operating in shared hosting environments where privilege boundaries and request validation demand careful enforcement. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shortpixel over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57722MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS.
This issue affects Enable | Jul 1, 2026 | 5.9 | 29 | NO | NO |
CVE-2026-5714MEDIUM The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 due to insuf | Jun 9, 2026 | 6.4 | 29 | NO | NO |
CVE-2026-57342MEDIUM Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions. | Jul 2, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-56066MEDIUM Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions. | Jun 26, 2026 | 5.8 | 26 | NO | NO |
CVE-2023-32512HIGH Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin <= 3.7.1 versions. | Nov 9, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-0255HIGH The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected si | Feb 13, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-4643HIGH The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection wh | Oct 16, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-48044HIGH Missing Authorization vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Exploiting Incorrectly Configured Access Control Security Levels.This | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-0334MEDIUM The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scrip | Feb 27, 2023 | 6.1 | 24 | NO | YES |
CVE-2025-9496MEDIUM The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due | Oct 11, 2025 | 6.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shortpixel.
Media articles that mention a CVE ID that affects a product developed by Shortpixel — matched by CVE ID, not by vendor name.