cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forewww-image-optimizer ewww-image-optimizer

Direction: ascending
Jun 07, 2024

EWWW Image Optimizer # CVE-2023-40600

CVE, Research URL

CVE-2023-40600

Application

EWWW Image Optimizer

Date
Nov 30, 2023
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.
Affected versions
max 7.2.1.
Status
vulnerable

EWWW Image Optimizer # CVE-2016-20010

CVE, Research URL

CVE-2016-20010

Application

EWWW Image Optimizer

Date
May 05, 2021
Research Description
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
Affected versions
max 2.8.5.
Status
vulnerable

EWWW Image Optimizer # CVE-2014-6243

CVE, Research URL

CVE-2014-6243

Application

EWWW Image Optimizer

Date
Oct 10, 2014
Research Description
Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message.
Affected versions
max 2.0.2.
Status
vulnerable

EWWW Image Optimizer # CVE-2020-36750

CVE, Research URL

CVE-2020-36750

Application

EWWW Image Optimizer

Date
Jul 12, 2023
Research Description
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 5.9.
Status
vulnerable

EWWW Image Optimizer # CVE-2024-31924

CVE, Research URL

CVE-2024-31924

Application

EWWW Image Optimizer

Date
Apr 10, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affects EWWW Image Optimizer: from n/a through <= 7.2.3.
Affected versions
max 7.3.0.
Status
vulnerable
Jun 25, 2025

EWWW Image Optimizer # PSC-2025-64576

PSC, Research URL

PSC-2025-64576

Application

EWWW Image Optimizer

Date
Jun 25, 2025
Research Description
EWWW Image Optimizer (EWWW IO) is a high-performance WordPress plugin designed to enhance site speed and SEO by automatically optimizing image files across your entire website. Whether you’re dealing with the WordPress Media Library, theme assets, or third-party plugin images, EWWW IO ensures that every image is compressed efficiently without compromising quality. The plugin supports a wide range of formats, including JPG, PNG, WebP, SVG, PDF, and the next-gen AVIF, with adaptive and intelligent conversion to deliver optimal file types for every use case. EWWW IO can perform all optimizations locally on your server using powerful image processing tools or offload them to specialized servers via Easy IO CDN. With features such as lazy loading, bulk optimization, WebP/AVIF conversion, and comprehensive plugin compatibility, it serves as a complete image performance suite. EWWW IO is not only built for speed but also engineered with strong security practices, having earned the Plugin Security Certification (PSC) from CleanTalk.
Affected versions
Min 8.7.6, max 8.7.6.
Status
SAFE & CERTIFIED
Jun 16, 2026

EWWW Image Optimizer # b215e1988ee64001cf0dc130dbc7fec4aa8b3af0

Application

EWWW Image Optimizer

Date
Sep 16, 2020
Research Description
EWWW Image Optimizer [ewww-image-optimizer] < 5.8.2 WordPress EWWW Image Optimizer plugin <= 5.8.1 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress EWWW Image Optimizer plugin (versions <= 5.8.1).
Affected versions
max 5.8.2.
Status
vulnerable

EWWW Image Optimizer # 20d5a6c2-d3af-4a17-8de1-4a6ee9ee055f

Application

EWWW Image Optimizer

Date
-
Research Description
EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1 EWWW Image Optimizer &lt; 7.2.1 - Sensitive Information Exposure The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settings.
Affected versions
max 7.2.1.
Status
vulnerable

EWWW Image Optimizer # 2cd0965f0b9f443a3dfed9bbddd27ad8c5e42c99

Application

EWWW Image Optimizer

Date
Jun 09, 2016
Research Description
EWWW Image Optimizer [ewww-image-optimizer] < 2.8.4 WordPress EWWW Image Optimizer Plugin <= 2.8.3 - Remote Code Execution Because of this vulnerability, attackers can create a backdoor or take a site down altogether. Upgrade this plugin.
Affected versions
max 2.8.4.
Status
vulnerable

EWWW Image Optimizer # e03420c55099714ac90da016761d318e5e1cb6db

Application

EWWW Image Optimizer

Date
-
Research Description
EWWW Image Optimizer [ewww-image-optimizer] < 5.9 404 Page Not Found
Affected versions
max 5.9.
Status
vulnerable

EWWW Image Optimizer # 375d3224d68a595fec7b30e651724921a34feceb

Application

EWWW Image Optimizer

Date
Sep 08, 2023
Research Description
EWWW Image Optimizer [ewww-image-optimizer] < 7.2.1 EWWW Image Optimizer <= 7.2.0 - Sensitive Information Exposure The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.2.0 due to the plugin saving debug logs in predictable locations. This can allow unauthenticated attackers to obtain information about installation paths, file permissions and various plugin settings.
Affected versions
max 7.2.1.
Status
vulnerable
Aug 20, 2026

EWWW Image Optimizer # CVE-2026-15446

CVE, Research URL

CVE-2026-15446

Application

EWWW Image Optimizer

Date
Aug 19, 2026
Research Description
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time.
Affected versions
max 8.7.4.
Status
vulnerable
Sep 04, 2026

EWWW Image Optimizer # CVE-2026-84773

CVE, Research URL

CVE-2026-84773

Application

EWWW Image Optimizer

Date
Sep 03, 2026
Research Description
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
Affected versions
max 8.7.7.
Status
vulnerable