CVE-2026-97067: WordPress EWWW Image Optimizer plugin <= 8.7.7 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.
Affected Software
1 affected component
EWWW EWWW Image Optimizer<=8.7.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/ewww-image-optimizerto a version that resolves this vulnerability.Fixed in 8.8.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who needs to be able to act for this issue to be exploited?
An attacker needs Contributor-level privileges in WordPress and must be able to induce user interaction. The vector is network-based, and the affected plugin versions are 8.7.7 and earlier.
2
What is the likely security impact if exploitation succeeds?
The vulnerability is rated medium severity with a CVSS score of 6.5. Successful exploitation can have low impact on confidentiality, integrity, and availability, and the scope is changed.