CVE-2026-1246 | ShortPixel Image Optimizer Plugin up to 6.4.2 on WordPress loadFile path traversal
A vulnerability classified as critical was found in ShortPixel Image Optimizer Plugin up to 6.4.2 on WordPress. Impacted is an unknown function. Executing a manipulation of the argument loadFile can lead to path traversal.
This vulnerability is registered as CVE-2026-1246. It is possible to launch the attack remotely. No exploit is available.