Sceawere
Vulnerability Detail
CVE-2026-103070UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ShortPixel Image Optimizer Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 4h ago
- Vendor
- ShortPixel
- Product
- ShortPixel Image Optimizer
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Stored XSS.This issue affects ShortPixel Image Optimizer: from n/a through 6.5.6.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T13:17:12.150Z",
"pubdate": "2026-10-08T13:17:12.150Z",
"executiveSummary": "The ShortPixel Image Optimizer plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw originates from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject and persist malicious scripts within the application context.\nThe vulnerability affects all versions of ShortPixel Image Optimizer from n/a through 6.5.6.\nAn attacker capable of exploiting this vulnerability can execute arbitrary JavaScript in the browser session of a victim, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive administrative cookies.\nExploitation requires the attacker to successfully inject the payload into a data field that is subsequently rendered by the plugin without sufficient sanitization or output encoding.\nThe risk is categorized as significant due to the potential for full compromise of the victim's interaction with the WordPress administrative dashboard.\nNo authentication is natively required for the initial payload injection if the input vector is reachable by unauthorized users, though specific contexts may vary based on the plugin's architectural design.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the application's failure to properly sanitize or encode user-provided input before rendering it back to the user within the administrative interface.\nThe root cause lies in the application's handling of data inputs within the ShortPixel Image Optimizer plugin that are stored in the database and later displayed in the WordPress dashboard without adequate output escaping.\nBecause the input is stored persistently, the malicious payload is delivered to any user—including administrators—who views the affected page, making this a high-impact persistent vector.\nThe attack flow begins when an attacker identifies an input field managed by the ShortPixel Image Optimizer that does not validate or sanitize input according to expected formats. The attacker crafts a malicious script payload (e.g., <script>alert('XSS')</script> or more sophisticated document.cookie exfiltration scripts) and submits it through the vulnerable input parameter.\nOnce submitted, the malicious script is stored in the database. When a target user (typically a site administrator) navigates to the administrative page where this data is rendered, the plugin echoes the stored content directly into the HTML document object model (DOM) of the browser.\nThe browser, interpreting the injected content as legitimate executable code rather than plain text, executes the script within the context of the site's origin. This allows the attacker to perform operations as the authenticated victim, such as modifying plugin settings, creating new administrative accounts, or capturing session tokens.\nThe vulnerability exists within the codebase of ShortPixel Image Optimizer versions from n/a through 6.5.6. The exploitation process does not necessarily require the attacker to bypass complex cryptographic protections; rather, it relies on the lack of context-aware output encoding (e.g., using WordPress functions like esc_html(), esc_attr(), or wp_kses()) on the server-side components responsible for generating the administrative UI.\nSuccessful exploitation results in full client-side control, where the attacker's script inherits the victim's privileges. Given that administrative users are the primary target for these UI-based vulnerabilities, the post-exploitation impact is severe, potentially leading to a total compromise of the WordPress site installation and the underlying server environment through plugin configuration manipulation or remote code execution via administrative dashboard features."
}