EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content
medium
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-le...
- CVSS:
- 6.4
- Affected:
- up to 8.7.3
- Fixed in:
- 8.7.4
- Disclosed:
- Aug 18, 2026
CVE-2026-15446 on NVD →
EWWW Image Optimizer <= 7.2.3 - Cross-Site Request Forgery
medium
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.3. This is due to missing or incorrect nonce validation on the check_for_optin() and check_for_optout() functions. This makes it possible for unauthenticated attackers to opt in and out of...
- CVSS:
- 4.3
- Affected:
- up to 7.2.3
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 10, 2024
CVE-2024-31924 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Exactly WWW EWWW Image Optimizer.This issue affects EWWW Image Optimizer: from n/a through 7.2.3.
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 10, 2024
CVE-2024-31924 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
- Disclosed:
- Nov 30, 2023
CVE-2023-40600 on NVD →
EWWW Image Optimizer <= 7.2.0 - Unauthenticated Sensitive Information Exposure via Debug Log
medium
The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.
- CVSS:
- 5.3
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.1
- Disclosed:
- Nov 14, 2023
CVE-2023-40600 on NVD →
EWWW Image Optimizer <= 7.2.0 - Sensitive Information Exposure
medium
The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settin...
- CVSS:
- 5.3
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
- Disclosed:
- Sep 8, 2023
EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1
unknown
The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settin...
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
- Disclosed:
- Sep 8, 2023
EWWW Image Optimizer [ewww-image-optimizer] < 5.9
unknown
[en] The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a...
- Affected:
- up to 5.9
- Fixed in:
- 5.9
- Disclosed:
- Jul 12, 2023
CVE-2020-36750 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 5.9
unknown
- Affected:
- up to 5.9
- Fixed in:
- 5.9
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 2.8.5
unknown
[en] EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
- Disclosed:
- May 5, 2021
CVE-2016-20010 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 5.8.2
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress EWWW Image Optimizer plugin (versions <= 5.8.1).
- Affected:
- up to 5.8.2
- Fixed in:
- 5.8.2
- Disclosed:
- Sep 16, 2020
EWWW Image Optimizer <= 5.8.1 - Cross-Site Request Forgery Bypass
medium
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forg...
- CVSS:
- 4.3
- Affected:
- up to 5.8.1
- Fixed in:
- 5.9
- Disclosed:
- Sep 6, 2020
CVE-2020-36750 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 2.8.4
unknown
Because of this vulnerability, attackers can create a backdoor or take a site down altogether.
Upgrade this plugin.
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Jun 9, 2016
EWWW Image Optimizer <= 2.8.4 - Remote Code Execution
critical
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5. Version 2.8.4 provides a partial fix.
- CVSS:
- 9.6
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Jun 8, 2016
CVE-2016-20010 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 2.0.2
unknown
[en] Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message...
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Oct 10, 2014
CVE-2014-6243 on NVD →
EWWW Image Optimizer <= 2.0.1 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message.
- CVSS:
- 6.1
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Oct 9, 2014
CVE-2014-6243 on NVD →
EWWW Image Optimizer [ewww-image-optimizer] < 5.9
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 5.9
- Fixed in:
- 5.9
EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1
unknown
The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settin...
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database