PT-2026-103039 · WordPress · Ewww Image Optimizer

·

CVE-2026-91051

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EWWW Image Optimizer WordPress plugin versions prior to 8.8.0
Description Authenticated users with author-level permissions can store a serialized value in a post meta field. This value is deserialized when the post is rendered, enabling PHP Object Injection. This process can lead to remote code execution if a suitable gadget chain is present. PHP Object Injection is a vulnerability where untrusted input is passed to the unserialize() function, allowing an attacker to manipulate the logic of the application by injecting malicious objects.
Recommendations Update EWWW Image Optimizer WordPress plugin to version 8.8.0 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91051

Affected Products

Ewww Image Optimizer