What is CVE-2026-15345?
CVE-2026-15345 is an authorization bypass vulnerability in the ShortPixel Adaptive Images plugin for WordPress (up to version 3.11.5). Due to improper verification of user permissions, an authenticated user can perform unauthorized actions. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-15345, WordPress üçün ShortPixel Adaptive Images plaginində (3.11.5-ə qədər) aşkarlanmış authorization bypass zəifliyidir. Plugin istifadəçinin icazəsini düzgün yoxlamadığı üçün autentifikasiya olunmuş istifadəçilər icazəsiz əməliyyatlar apara bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which plugin is affected by CVE-2026-15345 and what is the root cause?
The vulnerability affects the ShortPixel Adaptive Images plugin for WordPress (up to version 3.11.5). The root cause is improper verification of user permissions, leading to authorization bypass.
What is the recommended mitigation for CVE-2026-15345?
To protect against the vulnerability, it is recommended to update the ShortPixel Adaptive Images plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.