{"error":0,"message":null,"data":{"name":"EWWW Image Optimizer","plugin":"ewww-image-optimizer","link":"https:\/\/wordpress.org\/plugins\/ewww-image-optimizer\/","latest":"1788286380","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"1fb89dab3afeaa788a1729118ca04aa9edbdf2a32581ba531a0cf8f16947a51b","name":"EWWW Image Optimizer [ewww-image-optimizer] < 2.8.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-20010","name":"CVE-2016-20010","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-20010","description":"[en] EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.","date":"2021-05-05"},{"id":"7a822ba632de49a239d11b98799f6e6f19083ece","name":"EWWW Image Optimizer <= 2.8.4 - Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-284-remote-code-execution","description":"EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5. Version 2.8.4 provides a partial fix.","date":"2016-06-08"},{"id":"a7a49793-f1ba-483c-9b10-45e0a7ca42e6","name":"EWWW Image Optimizer &lt;= 2.8.3 - Remote Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/a7a49793-f1ba-483c-9b10-45e0a7ca42e6","description":"The EWWW Image Optimizer WordPress plugin was affected by a Remote Code Execution security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"10.0","severity":"c","exploitable":"3.9","impact":"6.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"10.0","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"6.0"}}},{"uuid":"4c10d4c7a7f82d730b294111d583f949e718ea41816db3450efadc27f8c3f8bd","name":"EWWW Image Optimizer [ewww-image-optimizer] < 2.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-6243","name":"CVE-2014-6243","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-6243","description":"[en] Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin\/options-general.php, which is not properly handled in a pngout error message.","date":"2014-10-10"},{"id":"4f0c9cd7987d71e217b96b367fba73ba226a46b8","name":"WordPress EWWW Image Optimizer Plugin <= 2.0.1 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ewww-image-optimizer\/vulnerability\/wordpress-ewww-image-optimizer-plugin-2-0-1-xss","description":"Because of this vulnerability, the attackers can inject arbitrary web script or HTML via the \"error\" parameter in the ewww-image-optimizer.php page to wp-admin\/options-general.php.\nUpdate the plugin.","date":"2014-09-04"},{"id":"17401705-5f44-47d6-920e-ec058d426114","name":"EWWW Image Optimizer 2.0.1 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/17401705-5f44-47d6-920e-ec058d426114","description":"The EWWW Image Optimizer WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"214b1e0d11bf14d3e2b6fbcb9f453df9826b90de","name":"EWWW Image Optimizer <= 2.0.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-201-reflected-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin\/options-general.php, which is not properly handled in a pngout error message.","date":"2014-10-09"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7da01269205b458ee7d381afb061b426aa0d90bce589ff7bef93dc213a6d4aba","name":"EWWW Image Optimizer [ewww-image-optimizer] < 5.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b215e1988ee64001cf0dc130dbc7fec4aa8b3af0","name":"WordPress EWWW Image Optimizer plugin <= 5.8.1 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ewww-image-optimizer\/vulnerability\/wordpress-ewww-image-optimizer-plugin-5-8-1-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress EWWW Image Optimizer plugin (versions <= 5.8.1).","date":"2020-09-16"}],"impact":[]},{"uuid":"07f06c87ec3c9db0d818fff23ccf0f09cac98c0ae524a853fde3d7c0e0b4b75f","name":"EWWW Image Optimizer [ewww-image-optimizer] < 2.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2cd0965f0b9f443a3dfed9bbddd27ad8c5e42c99","name":"WordPress EWWW Image Optimizer Plugin <= 2.8.3 - Remote Code Execution","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ewww-image-optimizer\/vulnerability\/wordpress-ewww-image-optimizer-plugin-2-8-3-remote-code-execution","description":"Because of this vulnerability, attackers can create a backdoor or take a site down altogether.\nUpgrade this plugin.","date":"2016-06-09"}],"impact":[]},{"uuid":"3174e7f340e775efe0f995a184187a893e358fb285da50b0d24127ac4a44d3be","name":"EWWW Image Optimizer [ewww-image-optimizer] < 5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e03420c55099714ac90da016761d318e5e1cb6db","name":"404 Page Not Found","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/various-affected-software-various-versions-cross-site-request-forgery-bypass","description":"","date":null}],"impact":[]},{"uuid":"c7ec2d09dbedd51dd415e48e334ef8c8df300782d5336d980e6a3d367912ad52","name":"EWWW Image Optimizer [ewww-image-optimizer] < 5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-4342","name":"CVE-2021-4342","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-4342","description":"CVE split into individual CVE IDs for each software record.","date":"2023-06-07"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"}}},{"uuid":"cc43016ba1ac9786e27d456e73f7f69418bfa96509e147aa42450eca85ab9a98","name":"EWWW Image Optimizer [ewww-image-optimizer] < 5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36750","name":"CVE-2020-36750","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36750","description":"[en] The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-07-12"},{"id":"d7b128b04e030f05973a0715d2cb41d484aaa33f","name":"EWWW Image Optimizer <= 5.8.1 - Cross-Site Request Forgery Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-581-cross-site-request-forgery-bypass","description":"The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2020-09-06"},{"id":"9fe6e899-17da-46fb-a0ff-cb6579b3dfa6","name":"EWWW Image Optimizer &lt; 5.9 - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/9fe6e899-17da-46fb-a0ff-cb6579b3dfa6","description":"The plugin does not correctly validate nonces in the ewww_ngg_bulk_init() function, resulting in a Cross-Site Request Forgery vulnerability. This may enable an unauthenticated user to perform bulk image optimization if they are able to deceive a site administrator into clicking on a manipulated link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"88510149eeed7c3236e29643d30ca9400e7972f5a493cffe1322db4b511bad1e","name":"EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"375d3224d68a595fec7b30e651724921a34feceb","name":"EWWW Image Optimizer <= 7.2.0 - Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-720-sensitive-information-exposure","description":"The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settings.","date":"2023-09-08"}],"impact":[]},{"uuid":"e9deb6f604ff1bd80656093f32601cbae1e1d9a626ff0a1a9193bfe34ae6c0b1","name":"EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-40600","name":"CVE-2023-40600","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-40600","description":"[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer.\u00a0It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n\/a through 7.2.0.","date":"2023-11-30"},{"id":"79b21bf6225eda42a71a9c3e50a2e3cd4fbbffae","name":"WordPress  EWWW Image Optimizer Plugin  <= 7.2.0 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ewww-image-optimizer\/vulnerability\/wordpress-ewww-image-optimizer-plugin-7-2-0-sensitive-data-exposure-vulnerability","description":"Update the WordPress EWWW Image Optimizer plugin to the latest available version (at least 7.2.1).\nMika discovered and reported this Sensitive Data Exposure vulnerability in WordPress EWWW Image Optimizer Plugin.  This vulnerability has been fixed in version 7.2.1.","date":"2023-11-14"},{"id":"11c25aa8cd56923ca83c4741b3ad7379489bae9d","name":"EWWW Image Optimizer <= 7.2.0 - Unauthenticated Sensitive Information Exposure via Debug Log","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-720-unauthenticated-sensitive-information-exposure-via-debug-log","description":"The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.","date":"2023-11-14"},{"id":"386b261c-5366-43e5-9f0c-e418dc5b6b14","name":"EWWW Image Optimizer &lt; 7.2.1 - Unauthenticated Sensitive Information Exposure via Debug Log","link":"https:\/\/wpscan.com\/vulnerability\/386b261c-5366-43e5-9f0c-e418dc5b6b14","description":"The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d176e874ba56379d4f76be1f31029925c25e4a5350d2f1256cb6ba8af68b04bb","name":"EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"20d5a6c2-d3af-4a17-8de1-4a6ee9ee055f","name":"EWWW Image Optimizer &lt; 7.2.1 - Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/20d5a6c2-d3af-4a17-8de1-4a6ee9ee055f","description":"The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settings.","date":null}],"impact":[]},{"uuid":"b1959ec0c39e186ee52cb415c9055e24b7baf38beac29e47cf0ca06c8b64be3c","name":"EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-31924","name":"CVE-2024-31924","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-31924","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affects EWWW Image Optimizer: from n\/a through <= 7.2.3.","date":"2024-04-10"},{"id":"bec4facba7fd30a404fa9cf802c973483d9898b4","name":"WordPress  EWWW Image Optimizer Plugin    <= 7.2.3 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ewww-image-optimizer\/vulnerability\/wordpress-ewww-image-optimizer-plugin-7-2-3-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress EWWW Image Optimizer plugin to the latest available version (at least 7.3.0).\nDhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress EWWW Image Optimizer Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 7.3.0.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"ace0a627a0ed2e9c5f44b579e7a0a9551a053865","name":"EWWW Image Optimizer <= 7.2.3 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-723-cross-site-request-forgery","description":"The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.3. This is due to missing or incorrect nonce validation on the check_for_optin() and check_for_optout() functions. This makes it possible for unauthenticated attackers to opt in and out of tracking via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-04-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8beb6cc21457f09785d6eb34a49a053e9bf193f6906a7f3e08721fa428fecc4b","name":"EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15446","name":"CVE-2026-15446","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15446","description":"[en] The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time.","date":"2026-08-19"},{"id":"9afb71b7038735fb677b7cbe2a18b4ff7322efe1","name":"EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-873-authenticated-contributor-stored-cross-site-scripting-via-data-script-lazy-load-attribute-in-post-content","description":"The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time.","date":"2024-04-10"},{"id":"a33f4451e8dcb5d71f153b07c5a7673965fdc7e1","name":"WordPress EWWW Image Optimizer Plugin <= 8.7.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ewww-image-optimizer\/vulnerability\/wordpress-ewww-image-optimizer-plugin-8-7-3-authenticated-contributor-stored-cross-site-scripting-via-data-script-lazy-load-attribute-in-post-content-vulnerability","description":"<p>WordPress EWWW Image Optimizer Plugin <= 8.7.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: EWWW Image Optimizer<\/p><p>Fixed in version 8.7.4 <\/p><p>Affected Version <= 8.7.3<\/p><p>CVE: CVE-2026-15446<\/p>","date":"2026-08-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a98b9ba657b22044bd3356de16c0b8dcc32919a6121b293abbcc9fef223ed119","name":"EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.7.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-84773","name":"CVE-2026-84773","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-84773","description":"[en] Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.","date":"2026-09-03"},{"id":"9e7bb95725f115f81978cc482d81889acdfe29c3","name":"EWWW Image Optimizer <= 8.7.6 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ewww-image-optimizer\/ewww-image-optimizer-876-unauthenticated-stored-cross-site-scripting","description":"The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.7.6. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7ac486342d8fbbbefc1b03330dbc80f1341f8e8a385168a2a2695ea5821010af","name":"EWWW Image Optimizer [ewww-image-optimizer] < 8.7.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.7.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-91011","name":"CVE-2026-91011","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-91011","description":"[en] The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.","date":"2026-09-17"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1789708097"}