Vulnerability Description
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ewww | Image Optimizer | < 2.8.5 |
References
- https://plugins.trac.wordpress.org/browser/ewww-image-optimizer/trunk/changelog.Release NotesThird Party Advisory
- https://www.wordfence.com/blog/2016/06/vulnerability-ewww-image-optimizer/Third Party Advisory
- https://plugins.trac.wordpress.org/browser/ewww-image-optimizer/trunk/changelog.Release NotesThird Party Advisory
- https://www.wordfence.com/blog/2016/06/vulnerability-ewww-image-optimizer/Third Party Advisory
FAQ
What is CVE-2016-20010?
CVE-2016-20010 is a vulnerability with a CVSS score of 10.0 (CRITICAL). EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
How severe is CVE-2016-20010?
CVE-2016-20010 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-20010?
Check the references section above for vendor advisories and patch information. Affected products include: Ewww Image Optimizer.