CVE-2025-68893: Hetworks WordPress Image Shrinker

Medium severity, CVSS 4.9. EPSS: 0.1% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through <= 1.1.0.

Affected products

  • Hetworks WordPress Image Shrinker: up to and including 1.1.0

Published 2025-12-29. Last modified 2026-10-07.