CVE-2026-39471: Shortpixel Image Optimizer
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Affected products
- Shortpixel Shortpixel Image Optimizer: up to and including 6.4.3
Published 2026-06-15. Last modified 2026-06-17.