CVE-2026-91051
Received Received - Intake

PHP Object Injection in EWWW Image Optimizer WordPress Plugin

Vulnerability report for CVE-2026-91051, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ewww_image_optimizer ewww_image_optimizer to 8.8.0 (exc)
ewww_image_optimizer ewww_image_optimizer 8.6.0
ewww_image_optimizer ewww_image_optimizer 8.7.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a PHP Object Injection flaw in the EWWW Image Optimizer WordPress plugin versions 8.6.0 to 8.7.7. Authenticated users with author-level permissions can exploit it by storing malicious serialized data in the 'eio_page_settings' post meta field. When the post is rendered, the data is deserialized, potentially leading to remote code execution if a suitable gadget chain exists in another installed plugin or theme.

Detection Guidance

Check the installed version of the EWWW Image Optimizer plugin. If it is between 8.6.0 and 8.7.7, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin directory for version details.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute arbitrary code on your server, potentially taking control of your WordPress site. It requires an attacker to have author-level access, but successful exploitation could lead to full site compromise, data theft, or further attacks on your server.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. A breach could result in legal penalties, reputational damage, and loss of trust from users or customers.

Mitigation Strategies

Update the EWWW Image Optimizer plugin to version 8.8.0 or later immediately. Remove author-level permissions for users who do not require them to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91051. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart