Junglewise Threat Intelligence

CVE-2026-91011: EWWW Image Optimizer WordPress plugin stored XSS in image attributes

CVE-2026-91011 · Severity: medium · CVSS 6.8 · Published 2026-09-17

Vendors: Elementor.

Executive brief

The EWWW Image Optimizer WordPress plugin is widely used to optimize images on websites. A flaw in versions before 8.7.7 allows authenticated authors and above to inject malicious JavaScript through image attributes that gets stored in published content, executing when any visitor views the page. This could lead to account compromise, data theft, or site defacement for affected visitors.

Technical details

The plugin contains a stored cross-site scripting (XSS) vulnerability in its page output rewriting functionality, specifically in how it processes and escapes image attribute values. Authenticated users with author-level access and above can exploit improper escaping to inject arbitrary JavaScript through image class attribute backreferences. The injected payload is stored in published content and executes in the browser of any user viewing the affected page. The vulnerability requires authentication and author-level permissions to exploit, but the impact affects all site visitors. The fix is available in version 8.7.7 and above.

Affected products

  • Elementor EWWW Image Optimizer before 8.7.7

Timeline

  • 2026-09-15: disclosed
  • 2026-09-17: advisory
  • 2026-09-15: patched: Fix released in version 8.7.7

References