Description
WordPress Plugin EWWW Image Optimizer is prone to a Denial of Service vulnerability. Exploiting this issue may allow an attacker to prevent the browsing session for a user, thus denying service to legitimate users. WordPress Plugin EWWW Image Optimizer version 6.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.0.2 or latest
References
https://gist.github.com/mmmdzz/03df5177afd04b32ac190eb7907f3834
https://plugins.svn.wordpress.org/ewww-image-optimizer/trunk/readme.txt
Related Vulnerabilities
WordPress 3.8.x Cross-Domain Flash Injection Vulnerability (3.8 - 3.8.24)
WordPress Plugin iQ Block Country Cross-Site Scripting (1.2.11)
WordPress Plugin Chamber Dashboard Member Manager Cross-Site Scripting (2.0.5)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6600)
WordPress Plugin Catch Infinite Scroll Security Bypass (1.8.1)