天下漏洞,尽知其名
MEDIUM

CVE-2026-92826 EWWW Image Optimizer 反射型跨站脚本漏洞

影响攻击者可诱骗用户点击链接,在其浏览器中执行任意脚本

AI 研判

EWWW Image Optimizer 是 WordPress 的图片优化插件。该插件在处理 REQUEST_URI 参数键时未充分过滤输入和转义输出,导致反射型跨站脚本漏洞。攻击者可通过构造恶意链接,在受害者浏览器中注入并执行任意 Web 脚本。

影响范围

EWWW Image Optimizer

影响 EWWW Image Optimizer 8.7.7 及之前的所有版本。

漏洞详情

漏洞类型为反射型跨站脚本(XSS),成因是插件对 REQUEST_URI 参数键缺乏充分的输入净化和输出转义。当 enable_help 选项启用时,插件会输出 HelpScout Beacon 脚本块,其中包含未转义的参数值。攻击者构造包含恶意脚本的 URL,诱使用户点击后脚本在用户浏览器中执行。

利用条件与风险

利用前提是 enable_help 选项处于启用状态,且攻击者需诱骗用户点击恶意链接。实战中可导致会话劫持、页面篡改或钓鱼等风险,CVSS 评分为 6.1。

修复建议

建议升级至 8.7.7 之后的修复版本;若暂无可用更新,可临时禁用 enable_help 选项以缓解风险。具体修复版本请以官方公告为准。

原始情报

The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires that the enable_help option is active, as the vulnerable HelpScout Beacon script block is only emitted when that setting is enabled.