Sceawere
Vulnerability Detail
CVE-2026-97246UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ShortPixel PHP Object Injection
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.9
- Creation Date
- 3h ago
- Vendor
- ShortPixel
- Product
- ShortPixel Image Optimizer
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.9",
"pubDate": "2026-09-30T13:17:36.563Z",
"pubdate": "2026-09-30T13:17:36.563Z",
"executiveSummary": "The ShortPixel Image Optimizer plugin for WordPress, in versions 6.5.5 and below, contains a critical PHP Object Injection vulnerability.\nThis vulnerability stems from insecure deserialization of user-supplied input, which can be manipulated by an authenticated attacker, specifically those with Subscriber-level privileges.\nThe flaw allows an attacker to instantiate arbitrary PHP objects within the application scope, potentially leading to unauthorized execution of code, file deletion, or other malicious actions depending on the presence of available 'gadget chains' within the WordPress environment.\nThe risk is categorized as high because it allows a low-privileged user to impact the integrity and availability of the entire WordPress installation.\nSuccessful exploitation requires the attacker to have an active Subscriber account on the target site and the ability to trigger the vulnerable code path through a crafted HTTP request.\nBy injecting a malicious serialized object, an attacker can hijack the application's flow, potentially resulting in Remote Code Execution (RCE) if suitable gadget chains are discovered within the site's codebase or active plugins.",
"technicalDetails": "The vulnerability is rooted in the unsafe handling of serialized data passed via user-controlled input to a deserialization function within the ShortPixel Image Optimizer plugin.\nIn PHP, the unserialize() function processes string data to recreate a PHP object. If the input string is manipulated to contain properties that define specific class instances, the application will attempt to instantiate those objects.\nIf the code contains 'magic methods'—such as __destruct(), __wakeup(), or __toString()—within the application's loaded classes (including those from the WordPress core, the theme, or other plugins), an attacker can leverage these methods to execute arbitrary code or perform unintended operations.\nThe attack flow begins with the attacker identifying the specific input field or endpoint that processes the serialized data. The attacker then constructs a malicious PHP serialized string, often representing an object of a class already present in the application memory space.\nBy carefully crafting this object, the attacker forces the application to execute code stored within a magic method when the object is instantiated or destroyed.\nBecause the plugin does not implement proper validation or sanitization of the serialized input before passing it to the deserialization routine, the application treats the attacker's payload as a trusted object, triggering the exploit.\nThe vulnerability is accessible to users with Subscriber privileges, significantly lowering the barrier to entry for exploitation. Once the malicious object is processed, the attacker gains the ability to leverage existing gadget chains to achieve outcomes such as arbitrary file read/write, unauthorized database modification, or Remote Code Execution.\nThe impact is severe, as the attacker can bypass security controls and gain significant control over the web application, leading to a complete compromise of the site's data and functionality.\nThe vulnerable component is the plugin's internal handling of state information or settings that are persisted as serialized data. As long as the serialized input is not cryptographically signed or properly validated against an allowlist, the application remains susceptible to PHP Object Injection attacks."
}