ImageMagick Engine

ImageMagick Engine has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 3 are fixed as of September 2026. Their average CVSS score is 8.3, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Deserialization Of Untrusted Data, OS Command Injection.

Every one of the 3 issues recorded for ImageMagick Engine has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (2) reported by Rasoul Jahanshahi. ImageMagick Engine is installed on roughly 60,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
8.3/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all ImageMagick Engine vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2022-3568

ImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to PHAR Deserialization

Read the full analysis

Vulnerability Records

3 records
ImageMagick Engine banner
Latestv2.0.0

ImageMagick Engine

Rickard Westerlind

Author

Rickard Westerlind

4.4(16)
88/100
Last Updated
2026-08-19 (25d ago)
Active Installs
60,000+
Downloads
1,439,224
Requires WP
6.4+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2010-09-21 (16y ago)

Dramatically improve the quality of re-sized images by making WordPress use ImageMagick instead of standard GD image library. Features Preserve embedded color profile in re-sized image Automatically recognize custom image sizes Allow regeneration of existing images (optionally for selected image sizes only) Configure image quality or use dynamically computed default value Optimize different image sizes for either quality or size Languages: English, French, German, Swedish, Turkish Requires either ImageMagick binary or Imagick PHP module. Contribute Code repo available on https://github.com/orangelabweb/imagemagick-engine/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C