WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-22288 — Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-22288 Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1 Path Traversal: '.../...//' Medium 4.1 < 3.17.1 3.17.1 2025-03-29

CVE-2025-22288

The Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.17.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform actions on files outside of the originally intended directory.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.