CVE-2026-89193
Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
| Vendor | unknown |
| Product | robin image optimizer |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown robin image optimizer
Be the first to know when new unknown vulnerabilities affecting unknown robin image optimizer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Robin Image Optimizer
2.0.0 < 2.0.8
References
Credits
Jakub Herman WPScan