CVE-2016-20010: Critical severity ewww image optimizer vulnerability
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-20010?
CVE-2016-20010 is a vulnerability in EWWW Image Optimizer before 2.8.5 that allows remote command execution due to a reliance on an unavailable protection mechanism involving boolval in PHP versions before 5.5.
How severe is CVE-2016-20010?
CVE-2016-20010 is considered critical, with a severity score of 10.
Which software versions are affected by CVE-2016-20010?
Versions up to and excluding 2.8.5 of EWWW Image Optimizer for WordPress are affected by CVE-2016-20010.
How can I fix CVE-2016-20010?
To fix CVE-2016-20010, update EWWW Image Optimizer for WordPress to version 2.8.5 or higher.
Where can I find more information about CVE-2016-20010?
You can find more information about CVE-2016-20010 in the following references: [Changelog](https://plugins.trac.wordpress.org/browser/ewww-image-optimizer/trunk/changelog.txt) and [Wordfence Blog](https://www.wordfence.com/blog/2016/06/vulnerability-ewww-image-optimizer/).