PT-2026-104492 · WordPress · Ewww Image Optimizer

·

CVE-2026-92826

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EWWW Image Optimizer versions prior to 8.7.8
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs via the REQUEST URI parameter key, enabling the injection of arbitrary web scripts that execute when a user is tricked into clicking a malicious link. This issue is only exploitable if the enable help option is active, as the vulnerable HelpScout Beacon script block is only emitted under this configuration.
Recommendations Update EWWW Image Optimizer to version 8.7.8 or later. As a temporary mitigation, disable the enable help option to prevent the vulnerable script block from being emitted.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92826

Affected Products

Ewww Image Optimizer