Reflected Cross-Site Scripting Vulnerability in Image Sizes on Demand Plugin for WordPress
CVE-2026-8622

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 June 2026

What is CVE-2026-8622?

The Image Sizes on Demand plugin for WordPress suffers from a vulnerability that allows attackers to exploit reflected cross-site scripting due to inadequate input sanitization and output escaping via the PHP_SELF server variable. Attackers can potentially inject arbitrary scripts that execute when an unsuspecting user interacts with maliciously crafted links. Although the payload only activates within the administrator context, it poses significant risks if executed, as it could lead to the unauthorized manipulation of site settings.

Affected Version(s)

Image Sizes on Demand 0 <= 1.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdulsamad Yusuf
.