CVE-2026-84773
massUnauthenticated XSS in EWWW Image Optimizer WordPress Plugin
CVE-2026-84773 is an unauthenticated cross-site scripting (XSS) flaw in the EWWW Image Optimizer plugin for WordPress, affecting all versions through 8.7.6. An attacker with no account on the site can trigger it via a crafted web request to the vulnerable component, and per the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C) no authentication or user interaction is required for the injected script to execute. Successful exploitation lets the attacker run arbitrary JavaScript in the browser context of the affected site, with the scope-changed rating indicating impact beyond the vulnerable component (e.g., visitors or admin sessions on the same site), rated as low confidentiality/integrity impact with no availability loss. All WordPress sites running EWWW Image Optimizer 8.7.6 or earlier are exposed. Exploitation status: no public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at 0.2% (6th percentile), indicating no known in-the-wild attacks so far.
What to do: Update EWWW Image Optimizer to the latest release beyond 8.7.6 (the patched version number is not specified in the available data); administrators should treat anything at or below 8.7.6 as vulnerable. Until updated, check plugin activity and web-server logs for anomalous unauthenticated requests targeting the plugin, and review any user-editable/stored values it renders for injected script. Monitor the plugin changelog and your security feed for the patched release and any emerging proof-of-concept, since EPSS may rise quickly if one is published.
| EWWW (ewww.io) EWWW Image Optimizer (WordPress plugin) | <= 8.7.6 (all versions up to and including 8.7.6) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.