Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

0N0Ise

Researcher fromcert.pl
#49760of 53,630
4.9Total CVSS
Vulnerabilities · 1
PT-2026-6032
4.9
2026-02-05
WordPress · Shortpixel Image Optimizer · CVE-2026-1246
**Name of the Vulnerable Software and Affected Versions** ShortPixel Image Optimizer plugin for WordPress versions prior to 6.4.3 **Description** The ShortPixel Image Optimizer plugin for WordPress is susceptible to unauthorized file access through a path traversal flaw. This issue stems from inadequate validation and sanitization of the `loadFile` parameter within the 'loadLogFile' AJAX action. Authenticated attackers possessing Editor-level access or higher can exploit this to read arbitrary files on the server, potentially exposing sensitive data like database credentials and authentication keys. **Recommendations** Update to version 6.4.3 or later.