CVE-2026-89190
Received Received - Intake

Privilege Escalation in Robin Image Optimizer WordPress Plugin

Vulnerability report for CVE-2026-89190, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
robin_image_optimizer robin_image_optimizer to 2.0.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Robin Image Optimizer WordPress plugin before version 2.0.8 allows users with subscriber-level access to view admin-only pages and disclose the plugin's stored settings. The issue occurs because the plugin does not check user capabilities before processing certain admin framework request handlers, specifically through the fy_ajax function.

Detection Guidance

Check if the Robin Image Optimizer plugin is installed and its version is below 2.0.8. Look for unauthorized access to admin-only pages via the fy_ajax function. Review server logs for suspicious requests targeting plugin settings.

Impact Analysis

An attacker with subscriber-level access could exploit this flaw to access sensitive plugin configurations, potentially exposing settings that may include API keys, optimization preferences, or other confidential data. This could lead to further compromise of the WordPress site or misuse of plugin features.

Compliance Impact

This vulnerability could impact compliance with GDPR or HIPAA if the disclosed plugin settings contain personal or sensitive data. Unauthorized access to such data may violate privacy regulations, leading to legal consequences, fines, or reputational damage for organizations handling protected information.

Mitigation Strategies

Update the Robin Image Optimizer plugin to version 2.0.8 or later immediately. Remove or restrict subscriber-level access if not required. Monitor for unusual admin page access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89190. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart