SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15253

MEDIUM · CVSS 6.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Easy Media Replace plugin for WordPress versions up to 0.2.0 is vulnerable due to inadequate sanitization of attachment titles, which can lead to cross-site scripting (XSS) attacks. This flaw allows users with Author roles or higher to inject malicious scripts that execute in the browsers of users with higher privileges accessing the media library. WordPress site administrators and security teams should prioritize this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-15253
Severity
MEDIUM
CVSS
6.8
EPSS
0.29%
WordPress

Original NVD Description

The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.