PT-2026-103039 · WordPress · Ewww Image Optimizer
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EWWW Image Optimizer WordPress plugin versions prior to 8.8.0
Description
Authenticated users with author-level permissions can store a serialized value in a post meta field. This value is deserialized when the post is rendered, enabling PHP Object Injection. This process can lead to remote code execution if a suitable gadget chain is present. PHP Object Injection is a vulnerability where untrusted input is passed to the
unserialize() function, allowing an attacker to manipulate the logic of the application by injecting malicious objects.Recommendations
Update EWWW Image Optimizer WordPress plugin to version 8.8.0 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ewww Image Optimizer