CVE-2026-92826

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires that the enable_help option is active, as the vulnerable HelpScout Beacon script block is only emitted when that setting is enabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-02); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-02: 1Mentions · 2026-10-03: 110-0210-03
Referenced assets2 URLs
Full discourse2 posts
  • 株式会社mgn@mgn_jpn

    🚨 EWWW Image Optimizer に脆弱性(深刻度 中) 100万サイト以上が利用 / CVSS 6.1 修正版 8.8.0 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-92826/

    00030527
    357 followersView on X
  • CVE@CVEnew

    CVE-2026-92826 The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.… https://www.cve.org/CVERecord?id=CVE-2026-92826

    00000484
    58.1K followersView on X

Explore more