Stored Cross-Site Scripting in ShortPixel Image Optimizer Plugin by WordPress
CVE-2026-4335

5.4MEDIUM

What is CVE-2026-4335?

The ShortPixel Image Optimizer plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This occurs due to inadequate output escaping when the attachment post_title is processed within the plugin. An authenticated user with Author-level access can manipulate attachment titles, potentially injecting malicious JavaScript through the HTML input element. When a higher-privileged user, such as an administrator, interacts with the ShortPixel AI editor popup, the injected script may execute, posing significant security risks to the WordPress installation.

Affected Version(s)

ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF 0 <= 6.4.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.