Impact
The EWWW Image Optimizer WordPress plugin before version 8.7.7 fails to escape image attribute values when rewriting page output. An authenticated author or higher can embed a malicious JavaScript payload into the class attribute of an image. The payload is stored in the database and subsequently executed in the browsers of all users who view the affected page, enabling session hijacking, phishing, or defacement. The vulnerability is a classic Stored XSS (CWE‑79).
Affected Systems
The vulnerability affects all installations of the EWWW Image Optimizer plugin with version numbers earlier than 8.7.7 running on WordPress sites. No specific operating‑system or server configuration is required beyond the standard WordPress setup.
Risk and Exploitability
The CVSS score is 6.8, indicating moderate severity. The EPSS score is less than 1% and the issue is not listed in the CISA KEV catalog, implying low current exploitation probability. The likely attack vector is authenticated, requiring the attacker to possess an author‑level or higher Active‑User role. If such privileges exist on the target site, an attacker can create or edit a post, inject the payload, and wait for browsing users to trigger it. No external network trigger or privilege escalation is required, so the vulnerability is primarily local to privileged site operators.
OpenCVE Enrichment