Description
The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.
Published: 2026-09-17
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via image class backreference allows author‑level users to inject arbitrary JavaScript into published content
Action: Assess Impact
AI Analysis

Impact

The EWWW Image Optimizer WordPress plugin before version 8.7.7 fails to escape image attribute values when rewriting page output. An authenticated author or higher can embed a malicious JavaScript payload into the class attribute of an image. The payload is stored in the database and subsequently executed in the browsers of all users who view the affected page, enabling session hijacking, phishing, or defacement. The vulnerability is a classic Stored XSS (CWE‑79).

Affected Systems

The vulnerability affects all installations of the EWWW Image Optimizer plugin with version numbers earlier than 8.7.7 running on WordPress sites. No specific operating‑system or server configuration is required beyond the standard WordPress setup.

Risk and Exploitability

The CVSS score is 6.8, indicating moderate severity. The EPSS score is less than 1% and the issue is not listed in the CISA KEV catalog, implying low current exploitation probability. The likely attack vector is authenticated, requiring the attacker to possess an author‑level or higher Active‑User role. If such privileges exist on the target site, an attacker can create or edit a post, inject the payload, and wait for browsing users to trigger it. No external network trigger or privilege escalation is required, so the vulnerability is primarily local to privileged site operators.

Generated by OpenCVE AI on September 18, 2026 at 04:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the EWWW Image Optimizer plugin to version 8.7.7 or newer, which contains the proper escaping fix.
  • Manually scan existing posts and media entries for injected class attributes; remove or sanitize any malicious JavaScript payloads.
  • If an immediate upgrade is not possible, reduce the number of author‑level users or apply custom configuration changes to disable the image attribute rewriting feature, and monitor for XSS attempts.

Generated by OpenCVE AI on September 18, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.
Title EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:26:09.671Z

Reserved: 2026-09-14T16:12:49.896Z

Link: CVE-2026-91011

cve-icon Vulnrichment

Updated: 2026-09-17T12:09:37.986Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:52.857

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-91011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')