CVE-2026-89193: Unknown Robin Image Optimizer

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.

Affected products

  • Unknown Robin Image Optimizer: from 2.0.0, before 2.0.8 (fixed in 2.0.8)

Published 2026-09-30. Last modified 2026-09-30.