CVE-2026-91072: EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EWWW Image Optimizerto a version that resolves this vulnerability.Fixed in 8.8.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Administrator-level access to the WordPress site. In a multisite network, this can allow an administrator of one site to affect WebP-derivative files belonging to another site they do not administer.
What files can be affected?
The vulnerable migration routine can rename or delete existing WebP-derivative image files outside the current site's uploads directory. The provided information does not indicate that non-WebP-derivative files are affected.
What should be prioritized for remediation?
Update EWWW Image Optimizer to version 8.8.0 or later. Until updating is possible, restrict Administrator-level access to trusted users, particularly on WordPress multisite deployments.