CVE-2026-39471: WordPress ShortPixel Image Optimizer plugin <= 6.4.3 - PHP Object Injection vulnerability
Published Jun 15, 2026
·Updated
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Affected Software
1 affected component
ShortPixel ShortPixel Image Optimizer<=6.4.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/shortpixel-image-optimizerto a version that resolves this vulnerability.Fixed in 6.4.4
Event History
Jun 15, 2026
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39471?
CVE-2026-39471 has a severity rating of high with a score of 7.2.
2
How do I fix CVE-2026-39471?
To resolve CVE-2026-39471, update the ShortPixel Image Optimizer plugin to version 6.4.4 or later.
3
What types of systems are affected by CVE-2026-39471?
CVE-2026-39471 affects WordPress sites using the ShortPixel Image Optimizer plugin version 6.4.3 or earlier.
4
What does CVE-2026-39471 exploit?
CVE-2026-39471 exploits a PHP Object Injection vulnerability in the ShortPixel Image Optimizer plugin.
5
When was CVE-2026-39471 published?
CVE-2026-39471 was published on June 15, 2026.