plugin

Ewww Image Optimizer Vulnerabilities

18 known security issues reported for the Ewww Image Optimizer WordPress plugin. Most recent disclosed Aug 18, 2026.

1 critical 6 medium

Running Ewww Image Optimizer on your site? Check whether your installed version is affected.

Scan your site free

EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content

medium

The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-le...

CVSS:
6.4
Affected:
up to 8.7.3
Fixed in:
8.7.4
Disclosed:
Aug 18, 2026

CVE-2026-15446 on NVD →

EWWW Image Optimizer <= 7.2.3 - Cross-Site Request Forgery

medium

The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.3. This is due to missing or incorrect nonce validation on the check_for_optin() and check_for_optout() functions. This makes it possible for unauthenticated attackers to opt in and out of...

CVSS:
4.3
Affected:
up to 7.2.3
Fixed in:
7.3.0
Disclosed:
Apr 10, 2024

CVE-2024-31924 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 7.3.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Exactly WWW EWWW Image Optimizer.This issue affects EWWW Image Optimizer: from n/a through 7.2.3.

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Apr 10, 2024

CVE-2024-31924 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Nov 30, 2023

CVE-2023-40600 on NVD →

EWWW Image Optimizer <= 7.2.0 - Unauthenticated Sensitive Information Exposure via Debug Log

medium

The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.

CVSS:
5.3
Affected:
up to 7.2.0
Fixed in:
7.2.1
Disclosed:
Nov 14, 2023

CVE-2023-40600 on NVD →

EWWW Image Optimizer <= 7.2.0 - Sensitive Information Exposure

medium

The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settin...

CVSS:
5.3
Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Sep 8, 2023

EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1

unknown

The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settin...

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Sep 8, 2023

EWWW Image Optimizer [ewww-image-optimizer] < 5.9

unknown

[en] The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a...

Affected:
up to 5.9
Fixed in:
5.9
Disclosed:
Jul 12, 2023

CVE-2020-36750 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 5.9

unknown
Affected:
up to 5.9
Fixed in:
5.9
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 2.8.5

unknown

[en] EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.

Affected:
up to 2.8.5
Fixed in:
2.8.5
Disclosed:
May 5, 2021

CVE-2016-20010 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 5.8.2

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress EWWW Image Optimizer plugin (versions <= 5.8.1).

Affected:
up to 5.8.2
Fixed in:
5.8.2
Disclosed:
Sep 16, 2020

EWWW Image Optimizer <= 5.8.1 - Cross-Site Request Forgery Bypass

medium

The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forg...

CVSS:
4.3
Affected:
up to 5.8.1
Fixed in:
5.9
Disclosed:
Sep 6, 2020

CVE-2020-36750 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 2.8.4

unknown

Because of this vulnerability, attackers can create a backdoor or take a site down altogether. Upgrade this plugin.

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jun 9, 2016

EWWW Image Optimizer <= 2.8.4 - Remote Code Execution

critical

EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5. Version 2.8.4 provides a partial fix.

CVSS:
9.6
Affected:
up to 2.8.4
Fixed in:
2.8.5
Disclosed:
Jun 8, 2016

CVE-2016-20010 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 2.0.2

unknown

[en] Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message...

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Oct 10, 2014

CVE-2014-6243 on NVD →

EWWW Image Optimizer <= 2.0.1 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message.

CVSS:
6.1
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Oct 9, 2014

CVE-2014-6243 on NVD →

EWWW Image Optimizer [ewww-image-optimizer] < 5.9

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 5.9
Fixed in:
5.9

EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1

unknown

The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settin...

Affected:
up to 7.2.1
Fixed in:
7.2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database