What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.11 versions.
Explanation of Vulnerability in Simple Terms
ImageRecycle PDF & Image Compression versions up to 3.1.11 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a user's browser when they interact with the affected component. The vulnerability requires user interaction and can affect other users or the site itself depending on context.
What an attacker can do
Inject and execute malicious JavaScript in users' browsers to steal data, modify page content, or perform actions on their behalf.
Potential impact on your site
Users visiting affected pages could have their sessions hijacked, credentials stolen, or be redirected to malicious sites.
Conditions required to exploit
No authentication required. The victim must click a malicious link or visit a compromised page containing the payload.
Key dates
External resources
Related vulnerabilities