Unauthenticated XSS Vulnerability in EWWW Image Optimizer Plugin by WordPress
CVE-2026-84773

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84773?

The EWWW Image Optimizer plugin for WordPress is susceptible to unauthenticated Cross Site Scripting (XSS) in versions up to 8.7.6. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by users, potentially compromising their session and data integrity. By exploiting this weakness, attackers can manipulate user interactions and gain unauthorized access to sensitive information.

Affected Version(s)

EWWW Image Optimizer <= 8.7.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bekitousei | Patchstack Bug Bounty Program
.