OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-89193

HIGH · CVSS 7.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Robin Image Optimizer plugin for WordPress versions prior to 2.0.8 is vulnerable due to inadequate escaping of values in its HTML parser, which can lead to Cross-Site Scripting (XSS) attacks. This flaw allows unauthenticated users to inject malicious content that is executed in the browsers of all users, including administrators, viewing affected pages. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential security risks.

CVE
CVE-2026-89193
Severity
HIGH
CVSS
7.5
EPSS
0.22%
WordPress

Original NVD Description

The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.