{"id":"CVE-2026-89193","published":"2026-09-30T06:17:08.590","lastModified":"2026-09-30T06:17:08.590","description":"The Robin Image Optimizer  WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/3c90d1c5-fd45-4a82-9357-504d7a0e5adc/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}