Junglewise Threat Intelligence

CVE-2026-56066: ShortPixel Adaptive Images unauthenticated arbitrary file deletion

CVE-2026-56066 · Severity: medium · CVSS 5.8 · Published 2026-06-26

Vendors: ShortPixel.

Executive brief

A vulnerability in the ShortPixel Adaptive Images plugin for WordPress allows unauthorized individuals to delete files from a website's server. This plugin is typically used to optimize and serve images efficiently; however, an exploit could lead to the deletion of critical website files, potentially causing the site to crash or stop functioning entirely. This issue can be exploited remotely without needing any login credentials.

Technical details

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion in versions up to and including 3.11.4. This is caused by improper limitation of a pathname to a restricted directory (CWE-22), commonly known as path traversal. An attacker can exploit this by sending a specially crafted network request to the server, allowing them to delete files outside of the intended directory. This can lead to a denial-of-service condition if critical system or application files are removed. The vulnerability is resolved in version 3.11.5.

Affected products

  • ShortPixel ShortPixel Adaptive Images <= 3.11.4

Timeline

  • 2026-06-12: other: Vulnerability reported by researcher
  • 2026-06-25: advisory: Patchstack published advisory
  • 2026-06-26: disclosed: CVE published to NVD
  • 2026-06-26: patched: Fixed in version 3.11.5

References

Related threats