Impact
The ShortPixel Adaptive Images WordPress plugin versions 3.11.3 and earlier contain a cross‑site scripting flaw (CWE‑79). The vulnerability allows a subscriber to inject arbitrary JavaScript into the content that the plugin renders. The injected JavaScript is executed in the browsers of all users who view the affected content, enabling front‑end compromise such as session hijack, defacement, or phishing. No server‑side code execution or file modification is possible; the impact is limited to client‑side manipulation.
Affected Systems
All WordPress sites that have the ShortPixel Adaptive Images plugin installed at a version 3.11.3 or earlier are affected. The plugin is maintained by ShortPixel and is the sole component listed in the advisory.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium severity range. An EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the most likely attack vector is a malicious subscriber who submits content that the plugin processes; the injected script is delivered client‑side. Because the flaw does not provide server‑side execution, the threat is confined to the front end, but it can erode user trust and compromise site reputation.
OpenCVE Enrichment