<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:shortpixel:shortpixel_image_optimizer:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ashortpixelshortpixel_image_optimizerwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 06:03:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ashortpixelshortpixel_image_optimizerwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-17086 PHP Object Injection in ShortPixel Image Optimizer</title><link>https://feed.craftedsignal.io/briefs/2026-09-shortpixel-php-injection/</link><pubDate>Fri, 18 Sep 2026 06:03:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-shortpixel-php-injection/</guid><description>Authenticated attackers can exploit insecure deserialization in ShortPixel Image Optimizer versions 6.5.5 and below to execute arbitrary code if a POP chain is available via other plugins or themes.</description><content:encoded><![CDATA[<p>ShortPixel Image Optimizer for WordPress, version 6.5.5 and below, contains a PHP Object Injection vulnerability resulting from insecure deserialization of untrusted input. The flaw enables authenticated users with author-level access or higher to supply malicious serialized objects to the application. While the ShortPixel plugin does not inherently contain a Property Oriented Programming (POP) chain required to trigger exploitation, the vulnerability relies on the presence of secondary plugins or themes installed on the same WordPress instance that do contain a usable POP chain. If such a chain exists, an attacker could potentially achieve remote code execution, arbitrary file deletion, or sensitive data exfiltration. The severity of this issue is dependent on the overall plugin ecosystem of the host environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation requires an authenticated attacker with at least author-level permissions and the presence of a separate vulnerable plugin or theme. Impact varies based on the discovered POP chain but may result in total site compromise, including unauthorized file system access or remote code execution. The scope of impact is limited to the WordPress environments where this specific combination of vulnerable plugin and secondary exploit chain exists.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the ShortPixel Image Optimizer plugin to the latest available version beyond 6.5.5 to mitigate the deserialization vulnerability. Audit the WordPress environment to remove unused plugins and themes that may contain POP chains. Prioritize remediation based on the exposure of the administrative or author-level account interfaces and the overall plugin/theme attack surface.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>php-injection</category><category>deserialization</category></item></channel></rss>