
CVE-2026-7311 The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_co… https://www.cve.org/CVERecord?id=CVE-2026-7311
Post summary
The TinyPNG plugin for WordPress is vulnerable to arbitrary file deletion caused by insufficient file path validation, as documented in its CVE record.

