The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 30 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
Title Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-30T13:37:22.420Z

Reserved: 2026-09-11T07:19:40.657Z

Link: CVE-2026-89193

cve-icon Vulnrichment

Updated: 2026-09-30T13:22:58.437Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T06:17:08.590

Modified: 2026-09-30T16:28:31.510

Link: CVE-2026-89193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:45:17Z

Weaknesses