CVE

CVE-2014-6243 — EWWW Image Optimizer [ewww-image-optimizer] < 2.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2014-6243 EWWW Image Optimizer [ewww-image-optimizer] < 2.0.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 2.0.2 2.0.2 2014-09-04

CVE-2014-6243

The EWWW Image Optimizer plugin before version 2.0.2 contains a cross-site scripting flaw that allows attackers to inject malicious scripts or HTML code through the error parameter on the wp-admin/options-general.php page. The vulnerability exists because user input from this parameter is not sanitized before being displayed in pngout error messages, enabling attackers to execute arbitrary JavaScript in the context of an administrator's browser.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.