Executive brief
SEO Friendly Images is a WordPress plugin used to automatically optimize image attributes for search engines. A security vulnerability in this plugin allows an attacker with basic contributor-level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, the script could execute, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Vladimir Prelovac SEO Friendly Images plugin (seo-image) for WordPress. The flaw stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Contributor' or higher privileges can inject malicious scripts that execute in the context of a victim's browser when they interact with a crafted page or specific DOM elements. As of the advisory date, no official patch has been released, and the vulnerability affects all versions through 3.0.5.
Affected products
- Vladimir Prelovac SEO Friendly Images <= 3.0.5
Timeline
- 2026-01-19: other: Vulnerability reported by researcher Steven Julian
- 2026-02-18: advisory: Initial disclosure by Patchstack
- 2026-04-08: disclosed: CVE published to NVD