Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Aug 01, 2025

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Vulnerabilities

Review known vulnerability records for the WordPress plugin ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization (`shortpixel-adaptive-images`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-6626, CVE-2025-30853 and CVE-2024-35172, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
8
High or Critical
0
Patch Coverage
100%
Last Updated
Aug 02, 2025
Priority CVE Quick Links

Fast paths into ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
CVE-2023-0334 Medium 3.6.2
CVE-2023-0334 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Cross-Site Scripting

ShortPixel Adaptive Images <= 3.6.1 - Reflected Cross-Site Scripting

CVE-2024-35172 Medium 3.8.4
CVE-2024-35172 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Server-Side Request Forgery

ShortPixel Adaptive Images <= 3.8.3 - Authenticated (Admin+) Server-Side Request Forgery

CVE-2023-32512 Medium 3.7.2
CVE-2023-32512 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Cross-Site Request Forgery

ShortPixel Adaptive Images <= 3.7.1 - Cross-Site Request Forgery via shortpixel_ai_handle_page_action

CVE-2024-31230 Medium 3.8.3
CVE-2024-31230 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Vulnerability

ShortPixel Adaptive Images <= 3.8.2 - Missing Authorization in activate_ai_handler and deactivate_ai_handler

CVE-2025-6626 Medium 3.10.5
CVE-2025-6626 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Stored Cross-Site Scripting

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.10.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via API URL

CVE-2025-30853 Medium 3.10.1
CVE-2025-30853 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Vulnerability

ShortPixel Adaptive Images <= 3.10.0 - Missing Authorization

CVE-2024-4689 Medium 3.8.4
CVE-2024-4689 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Cross-Site Request Forgery

ShortPixel Adaptive Images <= 3.8.3 - Cross-Site Request Forgery

CVE-2022-29417 Medium 3.4.0
CVE-2022-29417 ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Vulnerability

ShortPixel Adaptive Images <= 3.3.1 - Subscriber+ Arbitrary Settings Update

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
8 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2025-6626, CVE-2025-30853 and CVE-2024-35172
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-6626
CVE-2025-6626: ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.10.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via API URL

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it po...

Published
Aug 01, 2025
Patched Release
3.10.5
Affected Versions
Versions up to 3.10.4
Next Step
Update to 3.10.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-30853
CVE-2025-30853: ShortPixel Adaptive Images <= 3.10.0 - Missing Authorization

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handleDeactivation() function in all versions up to, and including, 3.10.0. This makes it possible for authentic...

Published
Apr 01, 2025
Patched Release
3.10.1
Affected Versions
Versions up to 3.10.0
Next Step
Update to 3.10.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-35172
CVE-2024-35172: ShortPixel Adaptive Images <= 3.8.3 - Authenticated (Admin+) Server-Side Request Forgery

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.8.3 via the is_our_cdn() function. This makes it possible for unauthenticated attackers to make web reque...

Published
May 10, 2024
Patched Release
3.8.4
Affected Versions
Versions up to 3.8.3
Next Step
Update to 3.8.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4689
CVE-2024-4689: ShortPixel Adaptive Images <= 3.8.3 - Cross-Site Request Forgery

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the import-settings page. This makes it possible for unauthenticated attackers to i...

Published
May 09, 2024
Patched Release
3.8.4
Affected Versions
Versions up to 3.8.3
Next Step
Update to 3.8.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-31230
CVE-2024-31230: ShortPixel Adaptive Images <= 3.8.2 - Missing Authorization in activate_ai_handler and deactivate_ai_handler

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate_ai_handler and deactivate_ai_handler functions in versions up to, and including, 3.8.2. This makes it possible for unauthentica...

Published
Apr 02, 2024
Patched Release
3.8.3
Affected Versions
Versions up to 3.8.2
Next Step
Update to 3.8.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-32512
CVE-2023-32512: ShortPixel Adaptive Images <= 3.7.1 - Cross-Site Request Forgery via shortpixel_ai_handle_page_action

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the 'shortpixel_ai_handle_page_action' ajax action. This makes it possible for unauthen...

Published
May 08, 2023
Patched Release
3.7.2
Affected Versions
Versions before 3.7.2
Next Step
Update to 3.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-0334
CVE-2023-0334: ShortPixel Adaptive Images <= 3.6.1 - Reflected Cross-Site Scripting

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a debugging parameter in versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

Published
Feb 02, 2023
Patched Release
3.6.2
Affected Versions
Versions up to 3.6.1
Next Step
Update to 3.6.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-29417
CVE-2022-29417: ShortPixel Adaptive Images <= 3.3.1 - Subscriber+ Arbitrary Settings Update

Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin

Published
Apr 25, 2022
Patched Release
3.4.0
Affected Versions
Versions up to 3.3.1
Next Step
Update to 3.4.0 or newer if supported.