---
id: CVE-2026-91051
title: >-
  The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent
  authenticated users with author-level permissions from storing a serialized
  value in a post meta field that is deserialized when the post is rendered,
  allowing them …
summary: >-
  The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent
  authenticated users with author-level permissions from storing a serialized
  value in a post meta field that is deserialized when the post is rendered,
  allowing them …
severity: none
cwe:
  - CWE-502
product: EWWW Image Optimizer
affected:
  - ewww_image_optimizer >= 8.6.0 < 8.8.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:09.173'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91051'
references:
  - url: 'https://wpscan.com/vulnerability/e24a9497-8fb4-4067-8421-194725455d55/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.556Z'
---

## Overview

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
