CVE · Medium

CVE-2025-24810 — Simple Image Sizes [simple-image-sizes] < 3.2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24810 Simple Image Sizes [simple-image-sizes] < 3.2.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.2.4 3.2.4 2025-01-28

CVE-2025-24810

The Simple Image Sizes plugin for WordPress contains a security flaw that allows malicious code injection through admin settings in versions up to 3.2.2, due to inadequate input validation and output protection. As a result, authorized attackers with elevated privileges can embed malicious scripts into pages that will be executed when accessed by other users. This vulnerability specifically affects multi-site configurations or installations where HTML filtering is disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.