Recursos /
Plugins de WordPress /
Image Optimization
SEGURIDAD DE PLUGINS
¿Es seguro Image Optimization?
Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Image Optimization — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
image-optimization
- 1000000+ instalaciones activas
convert AVIFconvert webpimage compressionimage optimizationperformance
Estado de mantenimiento
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
2 CVEs conocidos registrados para Image Optimization.
Reportadas entre 2026 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-5821
|
Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.5 |
Control externo del nombre o la ruta de un archivo |
Alta
8,1
|
< 1.7.5
|
1.7.5 |
2026-07-01 |
—
|
|
CVE-2026-25387
|
Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.2 |
Falta de control de autorización |
Media
4,3
|
< 1.7.2
|
1.7.2 |
2026-02-19 |
—
|
CVE-2026-5821
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they are within the uploads directory. The plugin stores backup file paths in the image_optimizer_metadata post meta field and trusts these paths completely when deleting backups on the delete_attachment hook. An authenticated attacker with Author-level access can edit the image_optimizer_metadata post meta on their own attachments via WordPress's Custom Fields interface, injecting arbitrary absolute file paths into the backups array. When the attacker subsequently deletes the attachment, the plugin calls File_System::delete() on each path without validation. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server within the web server's filesystem permissions, potentially leading to denial of service, data loss, or security degradation.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-25387
The Image Optimizer by Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas
Verifica tu propio sitio WordPress
Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.