CVE-2026-91011
EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.
| Vendor | unknown |
| Product | ewww image optimizer |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ewww image optimizer
Be the first to know when new medium vulnerabilities affecting unknown ewww image optimizer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / EWWW Image Optimizer
0 < 8.7.7
References
Credits
Artus KG WPScan