Impact
The vulnerability occurs in the EWWW Image Optimizer plugin (versions up to 8.7.6) used within WordPress. It allows an attacker to inject arbitrary HTML or JavaScript into browser contexts without authentication. An attacker could execute malicious code in the victim's browser, leading to session hijacking, defacement or other client‑side compromise. This flaw is a classic reflected XSS and is classified as CWE-79.
Affected Systems
WordPress sites that have installed the EWWW Image Optimizer plugin version 8.7.6 or earlier are affected. The plugin is authored by Shane Bishop. Any installation using these versions, regardless of user role, is vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium‑to‑high severity. Based on the description, it is inferred that the likely attack vector is an unauthenticated request to the plugin, typically accessed via the WordPress admin or front‑end, allowing the attacker to craft a request that the plugin processes. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, which suggests no widespread exploitation is reported yet. Nevertheless, the potential for client‑side compromise makes the risk significant for exposed WordPress sites.
OpenCVE Enrichment