Reflected Cross-Site Scripting Vulnerability in Image Sizes on Demand Plugin for WordPress
CVE-2026-8622
6.1MEDIUM
What is CVE-2026-8622?
The Image Sizes on Demand plugin for WordPress suffers from a vulnerability that allows attackers to exploit reflected cross-site scripting due to inadequate input sanitization and output escaping via the PHP_SELF server variable. Attackers can potentially inject arbitrary scripts that execute when an unsuspecting user interacts with maliciously crafted links. Although the payload only activates within the administrator context, it poses significant risks if executed, as it could lead to the unauthorized manipulation of site settings.
Affected Version(s)
Image Sizes on Demand 0 <= 1.3