๐Ÿ” CVE Alert

CVE-2026-91072

UNKNOWN 0.0

EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.

Vendor unknown
Product ewww image optimizer
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ewww image optimizer

Be the first to know when new unknown vulnerabilities affecting unknown ewww image optimizer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / EWWW Image Optimizer
0 < 8.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c77770c5-d1af-47f6-9aee-a50d4a919732/

Credits

Karthik Ramakrishnan WPScan