CVE · Medium

CVE-2025-22288 — Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-22288 Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1 Path Traversal: '.../...//' Medium 4.1 < 3.17.1 3.17.1 2025-03-29

CVE-2025-22288

A flaw exists in Smush Image Optimization plugin for WordPress, affecting all versions prior to 3.17.1, which allows authorized users with elevated privileges to manipulate files beyond their designated storage area through a Directory Traversal vulnerability. This weakness enables attackers to access and potentially modify sensitive data outside the intended directory scope.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.