Stored Cross-Site Scripting in ShortPixel Image Optimizer Plugin by WordPress
CVE-2026-4335
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 March 2026
What is CVE-2026-4335?
The ShortPixel Image Optimizer plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This occurs due to inadequate output escaping when the attachment post_title is processed within the plugin. An authenticated user with Author-level access can manipulate attachment titles, potentially injecting malicious JavaScript through the HTML input element. When a higher-privileged user, such as an administrator, interacts with the ShortPixel AI editor popup, the injected script may execute, posing significant security risks to the WordPress installation.
Affected Version(s)
ShortPixel Image Optimizer β Optimize Images, Convert WebP & AVIF 0 <= 6.4.3