CVE Database /
CVE-2025-22288
CVE · Medium
CVE-2025-22288 — Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-22288
|
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1 |
Path Traversal: '.../...//' |
Medium
4.1
|
< 3.17.1
|
3.17.1 |
2025-03-29 |
—
|
CVE-2025-22288
A flaw exists in Smush Image Optimization plugin for WordPress, affecting all versions prior to 3.17.1, which allows authorized users with elevated privileges to manipulate files beyond their designated storage area through a Directory Traversal vulnerability. This weakness enables attackers to access and potentially modify sensitive data outside the intended directory scope.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings