PT-2026-78282 · WordPress · Easy Media Replace
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easy Media Replace WordPress plugin versions prior to 0.2.1
Description
Insufficient sanitization and escaping of attachment titles before they are output in an HTML attribute within the media library list view allows users with the Author role or higher to perform a Cross-Site Scripting (XSS) attack. This occurs when a higher privileged user views the media library, causing the injected arbitrary web scripts to execute in their browser.
Recommendations
Update the Easy Media Replace WordPress plugin to version 0.2.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Media Replace