WordPress Plugin Simple Image Sizes Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting vulnerability has been identified in the WordPress plugin Simple Image Sizes, affecting versions through 3.2.3. This vulnerability allows an arbitrary script to be executed in the web browser of an administrator accessing the settings screen.
Impact
Exploitation of this vulnerability could lead to stored cross-site scripting, where injected scripts are executed in the context of the user with administrative privileges.
Remediation
Users are advised to update the Simple Image Sizes plugin to version 3.2.4, which addresses this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.4exploitability
4.5remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
