Description
Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ShortPixel Adaptive Images WordPress plugin versions 3.11.3 and earlier contain a cross‑site scripting flaw (CWE‑79). The vulnerability allows a subscriber to inject arbitrary JavaScript into the content that the plugin renders. The injected JavaScript is executed in the browsers of all users who view the affected content, enabling front‑end compromise such as session hijack, defacement, or phishing. No server‑side code execution or file modification is possible; the impact is limited to client‑side manipulation.

Affected Systems

All WordPress sites that have the ShortPixel Adaptive Images plugin installed at a version 3.11.3 or earlier are affected. The plugin is maintained by ShortPixel and is the sole component listed in the advisory.

Risk and Exploitability

The CVSS score of 6.5 places the vulnerability in the medium severity range. An EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the most likely attack vector is a malicious subscriber who submits content that the plugin processes; the injected script is delivered client‑side. Because the flaw does not provide server‑side execution, the threat is confined to the front end, but it can erode user trust and compromise site reputation.

Generated by OpenCVE AI on July 21, 2026 at 11:59 UTC.

Remediation

Vendor Solution

Update the WordPress ShortPixel Adaptive Images Plugin to the latest available version (at least 3.11.4).


OpenCVE Recommended Actions

  • Update the ShortPixel Adaptive Images plugin to version 3.11.4 or later.
  • If updating is not possible, disable the ShortPixel Adaptive Images plugin entirely.
  • Limit image submissions to administrator users or other trusted roles to reduce exposure.
  • Configure a strict Content Security Policy that blocks inline script execution to mitigate any residual XSS payloads.

Generated by OpenCVE AI on July 21, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Shortpixel
Shortpixel shortpixel Adaptive Images
Wordpress
Wordpress wordpress
Vendors & Products Shortpixel
Shortpixel shortpixel Adaptive Images
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
Title WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Shortpixel Shortpixel Adaptive Images
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:56:19.868Z

Reserved: 2026-06-24T12:45:24.971Z

Link: CVE-2026-57342

cve-icon Vulnrichment

Updated: 2026-07-02T14:56:15.347Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')