Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac SEO Friendly Images seo-image allows DOM-Based XSS.This issue affects SEO Friendly Images: from n/a through <= 3.0.5.
Published: 2026-04-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Update
AI Analysis

Impact

This flaw allows a type of cross‑site scripting where malicious script code can be injected into the browser session of a visitor when a URL or a page served by the SEO Friendly Images plugin is loaded. The vulnerability arises from the plugin’s failure to neutralize user input during page rendering, a classic input validation weakness identified as CWE‑79. If exploited, a malicious payload could steal credentials, hijack sessions, deface the site, or execute arbitrary client‑side actions, compromising the confidentiality and integrity of the user’s browser environment.

Affected Systems

Vladimir Prelovac’s SEO Friendly Images WordPress plugin, versions from the earliest release up to and including 3.0.5, are impacted. Any installation of the plugin below 3.0.6 is considered vulnerable.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is considered moderate in severity, while an EPSS score of less than 1% indicates that it is unlikely to be frequently exploited in the wild. The flaw is not listed in the CISA KEV catalog. The attack requires user interaction with a victim’s browser, typically via a crafted link or embedded content that triggers the plugin’s processing of unsanitized input. As it is a DOM‑based exploitation, the attacker needs the victim to load the insecure page in order to trigger the malicious script.

Generated by OpenCVE AI on April 13, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SEO Friendly Images plugin to a version newer than 3.0.5

Generated by OpenCVE AI on April 13, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Vladimir Prelovac
Vladimir Prelovac seo Friendly Images
Wordpress
Wordpress wordpress
Vendors & Products Vladimir Prelovac
Vladimir Prelovac seo Friendly Images
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac SEO Friendly Images seo-image allows DOM-Based XSS.This issue affects SEO Friendly Images: from n/a through <= 3.0.5.
Title WordPress SEO Friendly Images plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Vladimir Prelovac Seo Friendly Images
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:52:03.811Z

Reserved: 2026-04-07T10:57:59.671Z

Link: CVE-2026-39665

cve-icon Vulnrichment

Updated: 2026-04-13T18:52:42.560Z

cve-icon NVD

Status : Deferred

Published: 2026-04-08T09:16:37.743

Modified: 2026-04-24T18:06:04.160

Link: CVE-2026-39665

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:38:44Z

Weaknesses