CyberRota Analysis
AI-GeneratedThe Robin Image Optimizer plugin for WordPress versions prior to 2.0.8 is vulnerable due to inadequate escaping of values in its HTML parser, which can lead to Cross-Site Scripting (XSS) attacks. This flaw allows unauthenticated users to inject malicious content that is executed in the browsers of all users, including administrators, viewing affected pages. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential security risks.
Original NVD Description
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.