CVE-2025-11378: ShortPixel Image Optimizer <= 6.3.4 - Authenticated (Contributor+) Settings Import/Export
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixelajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to export and import site options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11378?
CVE-2025-11378 has a medium severity rating due to unauthorized modification risks.
How do I fix CVE-2025-11378?
To fix CVE-2025-11378, update the ShortPixel Image Optimizer plugin to version 6.3.5 or later.
Who is affected by CVE-2025-11378?
CVE-2025-11378 affects all versions of the ShortPixel Image Optimizer plugin up to and including 6.3.4.
What type of vulnerability is CVE-2025-11378?
CVE-2025-11378 is an unauthorized modification of data vulnerability.
What action should I take regarding CVE-2025-11378?
Users of the ShortPixel Image Optimizer plugin should immediately upgrade to a secure version to mitigate CVE-2025-11378.