CVE-2026-84773: WordPress EWWW Image Optimizer plugin <= 8.7.6 - Cross Site Scripting (XSS) vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
Affected Software
1 affected component
WordPress EWWW Image Optimizer plugin<=8.7.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress EWWW Image Optimizer Pluginto a version that resolves this vulnerability.Fixed in 8.7.7
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication or existing WordPress account is required. The vulnerability is described as unauthenticated XSS and is reachable over the network.
2
Which plugin versions are affected?
EWWW Image Optimizer versions 8.7.6 and earlier are identified as affected. The provided data does not specify a fixed version.
3
What is the likely security impact?
The supplied CVSS vector rates the issue high at 7.2 and indicates low confidentiality and integrity impact, with no availability impact. Its scope is changed, meaning the impact may extend beyond the vulnerable component.