WordPress security by component
Image Optimizer – Optimize Images and Convert to WebP or AVIF
Plugin description
Image Optimizer – Optimize Images and Convert to WebP or AVIF is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2026; the highest CVE/CNA score is 8.1.
Plugin slug:
image-optimizationLatest vulnerability
CVE-2026-5821: Image Optimizer – Optimize Images and Convert to WebP or AVIF: Arbitrary file deletion
Image Optimizer – Optimize Images and Convert to WebP or AVIF is affected by arbitrary file deletion. Exploitation requires at least author-level access. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.7.4.
| Safe version |
|
||
|---|---|---|---|
| Jul 02, 2026 |
CVE-2026-5821
Image Optimizer – Optimize Images and Convert to WebP or AVIF: Arbitrary file deletion
Image Optimizer – Optimize Images and Convert to WebP or AVIF is affected by arbitrary file deletion. Exploitation requires at least author-level access. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.7.4.
|
> 1.7.4 |
CVE8.1
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25387
Image Optimizer by Elementor: A security weakness
Image Optimizer by Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|