« Volver al listado

Ewww

Ewww Image Optimizer: vulnerabilidades y CVE

Ewww Image Optimizer tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses5
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97067Media (6.5)0.22%—30 sept 2026
Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.
CVE-2026-91072Media (4.4)0.17%—30 sept 2026
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or…
CVE-2026-91051Media (6.6)0.35%—30 sept 2026
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is…
CVE-2026-84773Alta (7.2)0.28%—3 sept 2026
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
CVE-2026-15446Media (6.4)0.42%—19 ago 2026
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input…
CVE-2023-40600Alta (7.5)2.0%—30 nov 2023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.
CVE-2020-36750Media (4.3)0.38%—12 jul 2023
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init()…
CVE-2016-20010Crítica (10)3.7%—5 may 2021
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript2
  2. T1210 Exploitation of Remote Services2
  3. T1059 Command and Scripting Interpreter1
  4. T1189 Drive-by Compromise1
  5. T1190 Exploit Public-Facing Application1
  6. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.