CVE-2026-103070: WordPress ShortPixel Image Optimizer plugin <= 6.5.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Stored XSS.This issue affects ShortPixel Image Optimizer: from n/a through 6.5.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/shortpixel-image-optimiserto a version that resolves this vulnerability.Fixed in 6.6.0
Event History
Frequently Asked Questions
What access and conditions does an attacker need to exploit this issue?
The CVSS vector indicates the attack can be performed over the network with low attack complexity, but requires low-level privileges and user interaction.
What is the expected impact if exploitation succeeds?
The issue is rated as having low confidentiality, integrity, and availability impact. The scope is changed, meaning the impact can extend beyond the initially vulnerable security authority.
Is a fixed version or workaround identified in the available information?
No fixed version or mitigation is identified in the provided data. The affected range is listed as versions through 6.5.6.