Description
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to export and import site options.
Problem types
Product status
*
Timeline
2025-10-06: | Vendor Notified |
2025-10-17: | Disclosed |
Credits
Dmitrii Ignatyev
References
www.wordfence.com/...-e222-43fa-a14f-b9cbced6b8f5?source=cve
research.cleantalk.org/CVE-2025-11378
github.com/...ommit/74263060acafbaf63b4a34f339a8b0dc35f2cad9
plugins.trac.wordpress.org/...ptimiser&sfp_email=&sfph_mail=