PT-2026-51682 · WordPress · Image Sizes On Demand

Abdulsamad Yusuf

·

Published

2026-06-24

·

Updated

2026-06-24

·

CVE-2026-8622

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Image Sizes on Demand versions prior to 1.4
Description Insufficient input sanitization and output escaping in the PHP SELF server variable allow unauthenticated attackers to inject arbitrary web scripts. These scripts execute if a user is tricked into clicking a malicious link. The execution occurs only within the context of an administrator, as the settings page requires the manage options capability to render. Reflected Cross-Site Scripting is a flaw where a malicious script is reflected off a web application to the victim's browser.
Recommendations Update to a version later than 1.3.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8622

Affected Products

Image Sizes On Demand