What is CVE-2026-15446?
CVE-2026-15446 is a Stored Cross-Site Scripting (XSS) vulnerability in the EWWW Image Optimizer plugin for WordPress. Due to insufficient input sanitization and output escaping, authenticated attackers can inject malicious scripts via the 'data-script' Lazy Load attribute in post content, affecting all versions up to and including 8.7.3. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-15446 zəifliyi WordPress-in EWWW Image Optimizer plaginində aşkarlanmış Stored Cross-Site Scripting (XSS) qüsurudur. 8.7.3 versiyasına qədər olan plagində 'data-script' Lazy Load atributu vasitəsilə yetərsiz giriş sanitizasiyası səbəbindən autentifikasiyalı hücumçulara post məzmununa zərərli skript yerləşdirmək imkanı verir. Plaginin son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the EWWW Image Optimizer plugin are affected by CVE-2026-15446?
This Stored XSS vulnerability affects all versions of the plugin up to and including 8.7.3.
How can attackers inject malicious scripts using CVE-2026-15446?
Authenticated attackers can inject malicious scripts via the 'data-script' Lazy Load attribute in post content due to insufficient input sanitization in the plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.