---
id: CVE-2025-11378
title: >-
  The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin
  for WordPress is vulnerable to unauthorized modification of data due to a
  missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all
  versions u…
summary: >-
  The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin
  for WordPress is vulnerable to unauthorized modification of data due to a
  missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all
  versions u…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-862
published: '2025-10-18'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11378'
references:
  - url: >-
      https://github.com/short-pixel-optimizer/shortpixel-image-optimiser/commit/74263060acafbaf63b4a34f339a8b0dc35f2cad9
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3379473%40shortpixel-image-optimiser&new=3379473%40shortpixel-image-optimiser&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: 'https://research.cleantalk.org/CVE-2025-11378'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/1f7e9eb5-e222-43fa-a14f-b9cbced6b8f5?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00311
epssPercentile: 0.22031
ingestedAt: '2026-10-09T12:53:29.118Z'
---

## Overview

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to export and import site options.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
