Junglewise Threat Intelligence

CVE-2026-57342: ShortPixel Adaptive Images XSS in WordPress plugin

CVE-2026-57342 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Vendors: ShortPixel.

Executive brief

ShortPixel Adaptive Images, a WordPress plugin used to optimize and serve appropriately sized images, contains a security flaw that allows users with basic 'Subscriber' accounts to inject malicious scripts. If a site administrator or another user interacts with the affected area, these scripts could execute in their browser, potentially leading to unauthorized actions or data theft. This vulnerability could be used by attackers to redirect visitors to malicious websites or display unauthorized advertisements.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the ShortPixel Adaptive Images plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with Subscriber-level privileges to inject arbitrary JavaScript into the application. Successful exploitation requires a victim (such as an administrator) to perform a specific action, such as visiting a crafted page or clicking a malicious link, which triggers the execution of the script in the context of the victim's session. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 3.11.4.

Affected products

  • ShortPixel ShortPixel Adaptive Images <= 3.11.3

Timeline

  • 2026-04-29: disclosed: Reported by dodoh4t to Patchstack
  • 2026-06-29: advisory: Initial advisory published by Patchstack
  • 2026-07-02: advisory: NVD published the CVE record
  • 2026-06-29: patched: Version 3.11.4 released to address the vulnerability

References

Related threats