Description
WordPress Plugin EWWW Image Optimizer is prone to a Denial of Service vulnerability. Exploiting this issue may allow an attacker to prevent the browsing session for a user, thus denying service to legitimate users. WordPress Plugin EWWW Image Optimizer version 6.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.0.2 or latest
References
https://gist.github.com/mmmdzz/03df5177afd04b32ac190eb7907f3834
https://plugins.svn.wordpress.org/ewww-image-optimizer/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Business Card Cross-Site Scripting (1.0.0)
Drupal Core 9.0.x Security Bypass (9.0.0 - 9.0.5)
Caddy Web Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29718)
WordPress Plugin TAuto Poster includes Backdoor [Only if downloaded via the vendor website] (1.4.5)