An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13459
Reference (s):
- https://github.com/verbb/image-resizer/blob/craft-3/CHANGELOG.md

