
ShortPixel users: Update to 6.4.3 RIGHT NOW. CVE-2026-1246 just dropped. It’s a directory traversal bug that lets anyone download your wp-config.php. Your database passwords are at risk. Full technical breakdown and the red flags to look for on our TG: https://t.me/webhostmost Is 100kb of saved image space worth a full database leak? I don't think so. #WebHostMost
Post summary
The post announces a new directory traversal CVE affecting ShortPixel, warns that wp-config.php may be exposed, and urges users to immediately update to version 6.4.3.

