Arbitrary File Deletion Vulnerability in Image Optimizer Plugin for WordPress
CVE-2026-5821
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 July 2026
What is CVE-2026-5821?
The Image Optimizer plugin for WordPress has a vulnerability that allows authenticated users with Author-level permissions to delete arbitrary files from the server. This occurs because the plugin lacks proper validation of file paths in its backup deletion process. Specifically, the Image_Backup::remove() function uses backup file paths directly from the post meta without verifying if they reside in the allowed uploads directory. An attacker can exploit this by modifying the metadata of their attachments through the WordPress Custom Fields interface to inject malicious absolute paths. Consequently, when the attacker deletes their attachment, the plugin executes file deletion on these unvalidated paths, potentially leading to critical consequences such as denial of service, data loss, or overall security degradation.
Affected Version(s)
Image Optimizer β Optimize Images and Convert to WebP or AVIF 0 <= 1.7.4