What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ben.moody SrcSet Responsive Images for WordPress truenorth-srcset allows Reflected XSS.This issue affects SrcSet Responsive Images for WordPress: from n/a through <= 1.4.
Explanation of Vulnerability in Simple Terms
02Summary
The SrcSet Responsive Images plugin for WordPress contains a cross-site scripting (XSS) vulnerability in versions 1.4 and earlier. An attacker can inject malicious JavaScript that executes in the browsers of site visitors. The vulnerability requires user interaction—typically a victim clicking a crafted link—and can affect multiple users across the site. Update to a version newer than 1.4 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that runs in visitors' browsers, potentially stealing credentials or session tokens.
Potential impact on your site
04Site Impact
Visitors' browsers can be compromised; attackers may steal login credentials, deface content, or redirect users.
Conditions required to exploit
05Prerequisites
No authentication required. Victim must click a malicious link or visit an attacker-controlled page.
Key dates
06Disclosure timeline
November 9, 2024
CVE published
May 12, 2026
Record updated