What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions.
Explanation of Vulnerability in Simple Terms
ImageRecycle PDF & Image Compression versions up to 3.1.10 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a user's browser when they interact with the affected component. The vulnerability requires user interaction and can affect other users or the site itself depending on context.
What an attacker can do
Inject and execute malicious JavaScript in users' browsers to steal data, redirect traffic, or deface content.
Potential impact on your site
Site visitors may be compromised; attackers can steal session tokens, credentials, or redirect users to malicious sites.
Conditions required to exploit
User must visit a page or click a link containing the attacker's malicious payload; no authentication required.
Key dates
External resources
Related vulnerabilities