First published: Mon Feb 27 2023(Updated: )
The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
ShortPixel Adaptive Images | <3.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-0334.
The severity of CVE-2023-0334 is medium with a severity value of 6.1.
The ShortPixel Adaptive Images WordPress plugin before version 3.6.3 is affected by CVE-2023-0334.
CVE-2023-0334 can be used to exploit a Reflected Cross-Site Scripting vulnerability in the ShortPixel Adaptive Images plugin, potentially affecting high privilege users such as admins.
To mitigate CVE-2023-0334, it is recommended to update the ShortPixel Adaptive Images plugin to version 3.6.3 or later, which includes the necessary sanitization and escape mechanisms to prevent the vulnerability.