EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure
CVE-2023-40600
Verified
Description
The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.
Severity
Medium
Published Date
February 16, 2026
Template Author
shivam kamboj
CVE-2023-40600.yaml
5.0Severity
CVSS Metrics
References
https://nvd.nist.gov/vuln/detail/CVE-2023-40600https://patchstack.com/database/wordpress/plugin/ewww-image-optimizer/vulnerability/wordpress-ewww-image-optimizer-plugin-7-2-0-sensitive-data-exposure-vulnerabilityhttps://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ewww-image-optimizer/ewww-image-optimizer-720-unauthenticated-sensitive-information-exposure-via-debug-log
Remediation Steps
Remove debug information and update to the latest version of EWWW Image Optimizer.