CVE-2026-97246: WordPress ShortPixel Image Optimizer plugin <= 6.5.5 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
Affected Software
1 affected component
ShortPixel Image Optimizer<=6.5.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ShortPixel Image Optimizer Pluginto a version that resolves this vulnerability.Fixed in 6.5.6
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Subscriber-level access to a WordPress site using an affected ShortPixel Image Optimizer version. The available data does not indicate that unauthenticated visitors can exploit it.
2
Which versions are affected?
ShortPixel Image Optimizer versions 6.5.5 and earlier are identified as affected.
3
What is the potential impact?
Successful exploitation may expose limited confidentiality and integrity impact, with scope changed, but no availability impact is indicated by the provided CVSS vector.