CVE Database /
CVE-2025-22288
CVE · Medium
CVE-2025-22288 — Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-22288
|
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1 |
Path Traversal: '.../...//' |
Medium
4.1
|
< 3.17.1
|
3.17.1 |
2025-03-29 |
—
|
CVE-2025-22288
The Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.17.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform actions on files outside of the originally intended directory.
Source:
Wordfence
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings