WordPress Plugin Vulnerabilities

EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler

Description

The plugin does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.

Proof of Concept

Affects Plugins

Fixed in 8.8.0

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-28 (about 2 days ago)
Added
2026-09-28 (about 1 day ago)
Last Updated
2026-09-28 (about 1 day ago)

Other