CVE-2026-91072 PUBLISHED

EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler

Assigner: WPScan
Reserved: 14.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.

Product Status

Vendor Unknown
Product EWWW Image Optimizer
Versions Default: unaffected
  • affected from 0 to 8.8.0 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE