PHP Object Injection Vulnerability in ShortPixel Image Optimizer
CVE-2026-39471
7.2HIGH
What is CVE-2026-39471?
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to a PHP Object Injection attack in versions up to 6.4.3. This vulnerability allows attackers to manipulate object serialization, potentially leading to remote code execution or other malicious actions. Website owners using affected versions should update their plugin immediately to safeguard against exploitation.
Affected Version(s)
ShortPixel Image Optimizer <= 6.4.3