← back to popular plugins
wordfence / plugin · wp-smushit
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN
wp-smushit
total installs
1,000,000
total vulns
1
critical
0
high
0
medium
0
low
1
latest vuln
—
patched
1
unpatched
0
avg time to patch
—
vulnerabilities
(1)
Smush Image Compression and Optimization <= 3.17.0 - Authenticated (Admin+) Directory Traversal
low
✓ patched
cve id
CVE-2025-22288 ↗
cvss score
2.7
cwe
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
published
Mar 29, 2025
The Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.17.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform actions on files outside of the originally intended directory.