๐Ÿ” CVE Alert

CVE-2026-91051

UNKNOWN 0.0

EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .

Vendor unknown
Product ewww image optimizer
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ewww image optimizer

Be the first to know when new unknown vulnerabilities affecting unknown ewww image optimizer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / EWWW Image Optimizer
8.6.0 < 8.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e24a9497-8fb4-4067-8421-194725455d55/

Credits

Karthik WPScan