WordPress Plugin Vulnerabilities

Image Optimizer < 1.7.5 - Author+ Arbitrary File Deletion via Post Meta Field Injection

Description

The plugin does not validate backup file paths stored in attachment post meta before deleting them, allowing authenticated attackers with Author-level access and above to inject arbitrary absolute paths and delete arbitrary files on the server, potentially leading to denial of service or data loss.

Affects Plugins

Fixed in 1.7.5

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
Dmitrii Ignatyev
Verified
No

Timeline

Publicly Published
2026-07-01 (about 1 month ago)
Added
2026-07-01 (about 1 month ago)
Last Updated
2026-07-01 (about 1 month ago)

Other