Executive brief
EWWW Image Optimizer is a WordPress plugin that compresses and optimizes images for websites. An unauthenticated visitor can inject malicious JavaScript into affected sites, allowing them to steal data from other visitors, hijack accounts, or perform actions on behalf of site users without authentication.
Technical details
A stored or reflected cross-site scripting (XSS) vulnerability exists in EWWW Image Optimizer versions 8.7.6 and earlier. The vulnerability allows unauthenticated attackers to inject malicious scripts that execute in visitors' browsers. No authentication or special privileges are required to trigger the vulnerability. Successful exploitation can lead to session hijacking, credential theft, malware distribution, or defacement. The vulnerability has been patched in version 8.7.7 and later.
Affected products
- Exactly WWW EWWW Image Optimizer <= 8.7.6
Timeline
- 2026-09-03: disclosed
- 2026-09-02: patched: Patched in version 8.7.7