Stored Cross-Site Scripting in Flying Images Plugin for WordPress
CVE-2025-11927

4.4MEDIUM

What is CVE-2025-11927?

The Flying Images plugin for WordPress, specifically versions up to 2.4.14, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability when users access the admin settings. This vulnerability arises from the plugin's inadequate input sanitization and output escaping, allowing authenticated users with administrator-level permissions to inject malicious scripts into the pages. These injected scripts execute automatically whenever users visit the affected pages. Notably, only multi-site installations and those where unfiltered_html is disabled are impacted by this issue.

Affected Version(s)

Flying Images: Optimize and Lazy Load Images for Faster Page Speed * <= 2.4.14

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karuppiah Sabari Kumar
.
CVE-2025-11927 : Stored Cross-Site Scripting in Flying Images Plugin for WordPress