Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c4g-pv82-qr56

Опубликовано: 17 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.

EPSS

Процентиль: 15%
0.00235
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
nvd
2 дня назад

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.

EPSS

Процентиль: 15%
0.00235
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79