/Vulnerability Library

EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure

CVE-2023-40600
Verified

Description

The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.

Severity

Medium

Published Date

February 16, 2026

Template Author

shivam kamboj

CVE-2023-40600.yaml
5.0Severity

CVSS Metrics

References

https://nvd.nist.gov/vuln/detail/CVE-2023-40600https://patchstack.com/database/wordpress/plugin/ewww-image-optimizer/vulnerability/wordpress-ewww-image-optimizer-plugin-7-2-0-sensitive-data-exposure-vulnerabilityhttps://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ewww-image-optimizer/ewww-image-optimizer-720-unauthenticated-sensitive-information-exposure-via-debug-log

Remediation Steps

Remove debug information and update to the latest version of EWWW Image Optimizer.