CVE-2026-15446
The EWWW Image Optimizer plugin for WordPress contains a vulnerability that allows attackers with contributor-level access or higher to inject malicious scripts into pages. This is done by exploiting a weakness in the plugin's handling of lazy loading images, specifically through the use of a 'data-script' attribute in image elements. When a user accesses a page containing the injected image, the malicious script is executed, allowing the attacker to run arbitrary web code. The vulnerability affects all versions of the plugin up to and including 8.7.3.
Based on public CVE data (MITRE/NVD).