
WP Image Zoom Security & Risk Analysis
wordpress.org/plugins/wp-image-zoooomAwesome image zoom plugin for images in posts/pages and for WooCommerce products.
Is WP Image Zoom Safe to Use in 2026?
Generally Safe
Score 99/100WP Image Zoom has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-image-zoooom v1.61 plugin exhibits a mixed security posture. On the positive side, the code analysis reveals no critical or high severity taint flows, no dangerous functions, and all SQL queries utilize prepared statements. The plugin also includes a reasonable number of nonce and capability checks, and it does not perform external HTTP requests. However, significant concerns arise from the presence of an unprotected AJAX handler, which represents a direct entry point for potential exploitation without proper authorization verification. Furthermore, a concerningly low percentage of output escaping (24%) suggests a susceptibility to Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered directly on the page.
The vulnerability history of this plugin is a major red flag. Having two past medium severity vulnerabilities, specifically including Remote File Inclusion and CSRF, indicates a pattern of introducing exploitable flaws. While there are currently no unpatched CVEs, the nature of past vulnerabilities is concerning. The RFI vulnerability, in particular, is severe and could lead to arbitrary code execution. The presence of CSRF vulnerabilities also points to potential weaknesses in how user actions are validated. The plugin's reliance on the bundled TinyMCE library, while common, also presents a potential risk if the bundled version is outdated and contains known vulnerabilities.
In conclusion, while wp-image-zoooom v1.61 demonstrates some good security practices like prepared statements and limited external calls, the unprotected AJAX endpoint and the history of severe vulnerability types (RFI, CSRF) coupled with insufficient output escaping create a substantial risk. Users should exercise extreme caution, and immediate patching or removal should be considered until these issues are addressed and verified.
Key Concerns
- Unprotected AJAX handler identified
- Low output escaping percentage (24%)
- History of 2 medium severity CVEs
- Past vulnerability types: RFI and CSRF
- Bundled TinyMCE library (potential for outdated version)
WP Image Zoom Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Image Zoom <= 1.46 - Local File Inclusion
WP Image Zoom <= 1.23 - Cross-Site Request Forgery to Denial of Service
WP Image Zoom Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WP Image Zoom Attack Surface
AJAX Handlers 2
WordPress Hooks 27
Maintenance & Trust
WP Image Zoom Maintenance & Trust
Maintenance Signals
Community Trust
WP Image Zoom Alternatives
WC Disable Zoom / Lightbox features
wc-disable-zoom-lightbox-features
This plugin lets you disable / enable the new product gallery zoom / lightbox features in 3.0.
FlexiZoom – Product Image Zoom for WooCommercee
flexizoom-product-image-zoom-for-woocommerce
Awesome Zoom & Slider Plugin for WooCommerce product pictures.
Ultimate Product Gallery for WooCommerce
ultimate-product-gallery-for-woocommerce
Product Gallery Plugin for WooCommerce + Image Zoom
Product Gallery Slider, Additional Variation Images, Product Video, Product Image Zoom and Lightbox for WooCommerce – WooGallery
gallery-slider-for-woocommerce
🔥 All-in-One WooCommerce Product Image and Video Gallery Solution to Enhance Your Customers' Shopping Experience and Boost Sales Instantly! 🚀
YITH Essential Kit for WooCommerce #1
yith-essential-kit-for-woocommerce-1
The YITH Essential Kit for WooCommerce #1 plugin enhance your WordPress site with this group of impressive features for WooCommerce.
WP Image Zoom Developer Profile
5 plugins · 729K total installs
How We Detect WP Image Zoom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-image-zoooom/assets/css/image-zoooom.css/wp-content/plugins/wp-image-zoooom/assets/js/image-zoooom.jswp-image-zoooom/assets/css/image-zoooom.css?ver=wp-image-zoooom/assets/js/image-zoooom.js?ver=HTML / DOM Fingerprints
zoooomdata-zoom-imagedata-thumbnail-src