ImageMagick Engine
ImageMagick Engine has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 3 are fixed as of September 2026. Their average CVSS score is 8.3, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Deserialization Of Untrusted Data, OS Command Injection.
Every one of the 3 issues recorded for ImageMagick Engine has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Rasoul Jahanshahi. ImageMagick Engine is installed on roughly 60,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-3568ImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to PHAR Deserialization
Read the full analysisVulnerability Records

ImageMagick Engine
Author
Rickard Westerlind
Dramatically improve the quality of re-sized images by making WordPress use ImageMagick instead of standard GD image library. Features Preserve embedded color profile in re-sized image Automatically recognize custom image sizes Allow regeneration of existing images (optionally for selected image sizes only) Configure image quality or use dynamically computed default value Optimize different image sizes for either quality or size Languages: English, French, German, Swedish, Turkish Requires either ImageMagick binary or Imagick PHP module. Contribute Code repo available on https://github.com/orangelabweb/imagemagick-engine/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C