CVE · High

CVE-2017-15079 — Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 2.7.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-15079 Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 2.7.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.7.6 2.7.6 2017-09-21

CVE-2017-15079

The Smush image optimization plugin for WordPress contained a file traversal vulnerability that allowed unauthorized access to files outside the intended directory structure. This flaw affected versions prior to 2.7.6, where improper path validation could be exploited to read arbitrary files on the server. The vulnerability has been resolved in version 2.7.6 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.