CVE-2016-20010: Ewww Image Optimizer

Critical severity, CVSS 10.0. EPSS: 3.7% chance of exploitation in the next 30 days.

EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.

Affected products

  • Ewww Image Optimizer: before 2.8.5 (fixed in 2.8.5)

Published 2021-05-05. Last modified 2026-06-17.