CVE · Critical

CVE-2016-20010 — EWWW Image Optimizer [ewww-image-optimizer] < 2.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2016-20010 EWWW Image Optimizer [ewww-image-optimizer] < 2.8.5 Critical 10.0 < 2.8.5 2.8.5 2016-06-08

CVE-2016-20010

The EWWW Image Optimizer plugin versions prior to 2.8.5 contained a remote code execution vulnerability due to inadequate input validation that depended on the boolval function, a feature not present in PHP versions earlier than 5.5. While version 2.8.4 attempted to address this issue partially, the vulnerability persisted until the 2.8.5 release provided a complete resolution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.