Impact
This vulnerability is a reflected cross‑site scripting flaw in the dynamic image URL generator view of Wagtail’s admin panel. An editor account can craft a malicious URL. When a higher‑privilege user opens that URL in the admin interface, the script executes in that user’s browser with the administrator’s privileges, allowing the attacker to run arbitrary code within the trusted admin context.
Affected Systems
All installations of Wagtail older than the patched releases 7.0.8, 7.3.3, or 7.4.2 are affected. The issue exists regardless of whether the dynamic image serve feature is enabled, so every site running those legacy versions is vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, yet the EPSS score of less than 1 % reflects a very low likelihood of real‑world exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an internal user to open it, limiting the attack surface. Once triggered, the script runs as the viewing user, potentially enabling the attacker to perform any actions that user can perform.
OpenCVE Enrichment