Impact
The EWWW Image Optimizer plugin for WordPress contains an insufficiently sanitized REQUEST_URI parameter that is emitted as part of a HelpScout Beacon script block when the enable_help option is active. This flaw permits an unauthenticated attacker to insert arbitrary script code into a page that is subsequently rendered in the victim’s browser. If the victim follows a crafted link or otherwise triggers the URL, the malicious script executes with the privileges of the visitor’s session, enabling phishing, session hijacking, or theft of sensitive data. No privilege escalation inside the server or administrative access is required; the vulnerability is purely client‑side and depends on user interaction.
Affected Systems
All installations of the nosilver4u EWWW Image Optimizer plugin up to and including version 8.7.7 are affected. The vulnerability is tied to the plugin’s enable_help setting and its rendering of a HelpScout Beacon script block. Any WordPress site that has an older version of the plugin installed is potentially exposed.
Risk and Exploitability
The CVSS score of 6.1 classifies this as a moderate severity XSS flaw. EPSS data is unavailable, so the exact likelihood of exploitation cannot be quantified, but the lack of a mandatory authentication requirement and the need for only a user click make the attack surface relatively high. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. An attacker can exploit the flaw by crafting a malicious URL containing a specially constructed REQUEST_URI key; when a victim clicks the link, the browser loads the page with the injected script, achieving cross‑site scripting impact.
OpenCVE Enrichment