PT-2026-51682 · WordPress · Image Sizes On Demand
Abdulsamad Yusuf
·
Published
2026-06-24
·
Updated
2026-06-24
·
CVE-2026-8622
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Image Sizes on Demand versions prior to 1.4
Description
Insufficient input sanitization and output escaping in the
PHP SELF server variable allow unauthenticated attackers to inject arbitrary web scripts. These scripts execute if a user is tricked into clicking a malicious link. The execution occurs only within the context of an administrator, as the settings page requires the manage options capability to render. Reflected Cross-Site Scripting is a flaw where a malicious script is reflected off a web application to the victim's browser.Recommendations
Update to a version later than 1.3.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Image Sizes On Demand