Junglewise Threat Intelligence

CVE-2026-39665: Vladimir Prelovac SEO Friendly Images DOM-based XSS

CVE-2026-39665 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Executive brief

SEO Friendly Images is a WordPress plugin used to automatically optimize image attributes for search engines. A security vulnerability in this plugin allows an attacker with basic contributor-level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, the script could execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Vladimir Prelovac SEO Friendly Images plugin (seo-image) for WordPress. The flaw stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Contributor' or higher privileges can inject malicious scripts that execute in the context of a victim's browser when they interact with a crafted page or specific DOM elements. As of the advisory date, no official patch has been released, and the vulnerability affects all versions through 3.0.5.

Affected products

  • Vladimir Prelovac SEO Friendly Images <= 3.0.5

Timeline

  • 2026-01-19: other: Vulnerability reported by researcher Steven Julian
  • 2026-02-18: advisory: Initial disclosure by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References