CVE-2026-4335: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-4335 is a Stored Cross-Site Scripting (XSS) vulnerability in the ShortPixel Image Optimizer plugin for WordPress, affecting all versions up to and including 6.4.3. The flaw allows authenticated attackers with Author-level access or above to inject arbitrary JavaScript that executes when a higher-privileged user (e.g., an administrator) opens the ShortPixel AI editor popup for a poisoned attachment. It was published on March 26, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is insufficient output escaping (CWE-79) in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, AjaxController.php (line 435) retrieves an attachment's post_title from the database via get_post() and passes it directly to the view template (line 449), where it is rendered into an HTML <input> element's value attribute without applying WordPress's esc_attr() sanitization function (media-popup.php, line 139). Because WordPress permits Authors to set arbitrary attachment titles — including double-quote characters — via the REST API, a malicious author can craft a title that breaks out of the HTML attribute context and injects JavaScript event handlers. The injected script executes in the browser of any higher-privileged user who opens the ShortPixel AI editor popup (Background Removal or Image Upscale) for the poisoned attachment (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a higher-privileged user's browser session, such as an administrator. This can lead to session hijacking, credential theft, unauthorized administrative actions (e.g., creating rogue admin accounts, installing malicious plugins), and site defacement. While availability is not directly impacted, the confidentiality and integrity of the WordPress site and its data are at risk (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-4335 as of the available data. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability requires authenticated access at the Author level or above, and exploitation depends on a privileged user interacting with the poisoned attachment's editor popup, limiting opportunistic mass exploitation. It does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).

Exploitation steps

  1. Gain Author-level access: Obtain or compromise a WordPress account with at least Author-level privileges on the target site running ShortPixel Image Optimizer ≤ 6.4.3.
  2. Upload an attachment: Upload any image or media file to the WordPress media library using the Author account.
  3. Craft a malicious attachment title: Using the WordPress REST API (e.g., PATCH /wp-json/wp/v2/media/<attachment_id>), update the attachment's post_title to a payload that breaks out of the HTML value attribute, such as: " onmouseover="alert(document.cookie) or a more sophisticated payload that exfiltrates session cookies to an attacker-controlled server.
  4. Wait for privileged user interaction: The injected script executes when an administrator or other high-privileged user opens the ShortPixel AI editor popup (Background Removal or Image Upscale) for the poisoned attachment in the WordPress media library.
  5. Achieve objective: The executed JavaScript can steal session cookies, perform actions on behalf of the administrator (e.g., create a backdoor admin account), or redirect the victim to a malicious page (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing REST API PATCH or POST requests to /wp-json/wp/v2/media/<id> from Author-level accounts with unusual or encoded title values containing HTML special characters (e.g., ", >, <, onerror, onmouseover).
  • Database: Attachment records in wp_posts where post_title contains JavaScript event handler strings (e.g., onmouseover=, onerror=, <script>) or encoded equivalents.
  • Network: Outbound HTTP requests from administrator browsers to unexpected external domains shortly after accessing the WordPress media library or ShortPixel editor popup, potentially indicating cookie or credential exfiltration.
  • Browser/Session: Unexpected administrative actions (new admin user creation, plugin installation, settings changes) correlated with media library access sessions.

Mitigation and workarounds

Users should update the ShortPixel Image Optimizer plugin to a version beyond 6.4.3, which includes the fix applying proper esc_attr() escaping in media-popup.php. The patch was committed to the plugin repository (changeset 3490270) (WordPress Trac Changeset). As a temporary workaround where updating is not immediately possible, site administrators should restrict Author-level user accounts to trusted individuals only and monitor REST API activity for suspicious attachment title modifications. Enabling a Web Application Firewall (WAF) with XSS filtering rules can also help reduce risk (Wordfence).

Community reactions

Wordfence included CVE-2026-4335 in its weekly WordPress vulnerability report for the period of March 23–29, 2026, and Sucuri referenced it in its March 2026 vulnerability patch roundup (Wordfence Blog, Sucuri Blog). Community reaction has been limited given the medium severity rating and the requirement for authenticated access, with no significant controversy or widespread alarm noted in available sources.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management