CVE-2026-7311 | TinyPNG Plugin up to 3.6.13 on WordPress delete_converted_image_size convert.path path traversal

SecurityVulns

A vulnerability was found in TinyPNG Plugin up to 3.6.13 on WordPress. It has been rated as critical. This affects the function delete_converted_image_size. The manipulation of the argument convert.path leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-7311. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More