PT-2026-104492 · WordPress · Ewww Image Optimizer
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
EWWW Image Optimizer versions prior to 8.7.8
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs via the
REQUEST URI parameter key, enabling the injection of arbitrary web scripts that execute when a user is tricked into clicking a malicious link. This issue is only exploitable if the enable help option is active, as the vulnerable HelpScout Beacon script block is only emitted under this configuration.Recommendations
Update EWWW Image Optimizer to version 8.7.8 or later.
As a temporary mitigation, disable the
enable help option to prevent the vulnerable script block from being emitted.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ewww Image Optimizer