Vulnerabilities > Ewww

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-40600 Unspecified vulnerability in Ewww Image Optimizer
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.
network
low complexity
ewww
7.5
2023-07-12 CVE-2020-36750 Cross-Site Request Forgery (CSRF) vulnerability in Ewww Image Optimizer
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1.
network
low complexity
ewww CWE-352
4.3
2021-05-05 CVE-2016-20010 Unspecified vulnerability in Ewww Image Optimizer
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
network
low complexity
ewww
7.5