CVE · Medium

CVE-2026-15446 — EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15446 EWWW Image Optimizer [ewww-image-optimizer] < 8.7.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 8.7.4 8.7.4 2024-04-10

CVE-2026-15446

The EWWW Image Optimizer plugin for WordPress contains a vulnerability that allows attackers with contributor-level access or higher to inject malicious scripts into pages. This is done by exploiting a weakness in the plugin's handling of lazy loading images, specifically through the use of a 'data-script' attribute in image elements. When a user accesses a page containing the injected image, the malicious script is executed, allowing the attacker to run arbitrary web code. The vulnerability affects all versions of the plugin up to and including 8.7.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.