PT-2021-3639 · WordPress · Ewww Image Optimizer

Sean Murphy

·

Published

2021-05-05

·

Updated

2021-05-13

·

CVE-2016-20010

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EWWW Image Optimizer versions prior to 2.8.5
Description The issue is related to a flaw in the protection mechanism of the EWWW Image Optimizer plugin for WordPress, which can be exploited by a remote attacker to execute arbitrary code. This is because the plugin relies on a protection mechanism involving boolval, which is not available in PHP versions before 5.5.
Recommendations For versions prior to 2.8.5, update to version 2.8.5 or later to resolve the issue. As a temporary workaround, consider disabling the plugin until a patch is applied. Restrict access to the plugin's functionality to minimize the risk of exploitation.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03858
CVE-2016-20010

Affected Products

Ewww Image Optimizer