WordPress · Ewww Image Optimizer · CVE-2026-91051
**Name of the Vulnerable Software and Affected Versions**
EWWW Image Optimizer WordPress plugin versions prior to 8.8.0
**Description**
Authenticated users with author-level permissions can store a serialized value in a post meta field. This value is deserialized when the post is rendered, enabling PHP Object Injection. This process can lead to remote code execution if a suitable gadget chain is present. PHP Object Injection is a vulnerability where untrusted input is passed to the `unserialize()` function, allowing an attacker to manipulate the logic of the application by injecting malicious objects.
**Recommendations**
Update EWWW Image Optimizer WordPress plugin to version 8.8.0 or later.