sh1zen has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.4 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- Multi Uploader for Gravity Forms 1
- WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals 1
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-87796Critical· 9.8The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function66CVE-2026-6295Medium· 4.9The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.027
sh1zen vulnerabilities
CVEs affecting sh1zen, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-6295Medium· 4.9The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0
The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that,…
▾ Sunlitsh1zen · WP Optimizer – PageSpeed, Cache, Minify & Core Web VitalsEPSS 0.30%via NVD
CVE-2026-87796Critical· 9.8PoCThe Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked uplo…
▾ Abyssalsh1zen · Multi Uploader for Gravity FormsEPSS 0.61%via NVD