CVE-2025-22288: WordPress Smush Image Compression and Optimization plugin <= 3.17.0 - Directory Traversal vulnerability
Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22288?
CVE-2025-22288 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2025-22288?
To fix CVE-2025-22288, update the WPMU DEV Smush Image Compression and Optimization plugin to version 3.17.1 or later.
What does CVE-2025-22288 affect?
CVE-2025-22288 affects the WPMU DEV Smush Image Compression and Optimization plugin versions up to and including 3.17.0.
What type of vulnerability is CVE-2025-22288?
CVE-2025-22288 is a Path Traversal vulnerability that allows attackers to access restricted directories.
Is CVE-2025-22288 being actively exploited?
As of now, there are no confirmed reports of active exploitation of CVE-2025-22288.