Impact
The ShortPixel Adaptive Images plugin for WordPress has a flaw in the API URL setting, where input sanitization and output escaping are insufficient. Administrators can inject arbitrary scripts that the plugin stores; when any visitor loads a page that uses the affected setting, the script executes, resulting in stored XSS. Normal users cannot inject without administrator privileges.
Affected Systems
WordPress sites that run the ShortPixel Adaptive Images plugin version 3.10.3 or earlier on a multisite network and where the unfiltered_html capability has been disabled. The 3.10.4 release is not vulnerable and includes the necessary fixes.
Risk and Exploitability
This vulnerability has a CVSS score of 4.4 and an EPSS score below 1 %. It is not listed in the CISA KEV catalog. An attacker who has administrator access would need to exploit the stored XSS to deface pages, harvest credentials, or deploy additional payloads. Because the flaw only exists on multisite installs with unfiltered_html disabled, the attack surface is restricted, and exploitation chance remains low.
OpenCVE Enrichment
EUVD