Reflected Cross-Site Scripting in EWWW Image Optimizer for WordPress
CVE-2026-92826
6.1MEDIUM
What is CVE-2026-92826?
The EWWW Image Optimizer plugin for WordPress is susceptible to Reflected Cross-Site Scripting because of inadequate input sanitization and output escaping in all versions up to and including 8.7.7. This vulnerability allows unauthenticated attackers to inject arbitrary scripts through the REQUEST_URI parameter, particularly when the enable_help option is activated. Under this condition, a malicious actor can potentially manipulate users into executing harmful actions, such as clicking on malicious links, leading to the execution of unintended web scripts.
Affected Version(s)
EWWW Image Optimizer 0 <= 8.7.7