Arbitrary File Read Vulnerability in ShortPixel Image Optimizer Plugin for WordPress
CVE-2026-1246
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 February 2026
What is CVE-2026-1246?
The ShortPixel Image Optimizer plugin for WordPress contains a vulnerability allowing authenticated users with Editor-level access or higher to perform Arbitrary File Read via path traversal. This issue arises from inadequate validation and sanitization of the 'loadFile' parameter in the 'loadLogFile' AJAX action, exposing sensitive data on the server, including database credentials and authentication keys. Webmasters using affected versions should implement remediation measures to protect against potential data breaches.
Affected Version(s)
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF 0 <= 6.4.2