CVE-2026-89193 PUBLISHED

Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser

Assigner: WPScan
Reserved: 11.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.

Product Status

Vendor Unknown
Product Robin Image Optimizer
Versions Default: unaffected
  • affected from 2.0.0 to 2.0.8 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE