CVE-2026-15253
PoC nicheStored XSS in Easy Media Replace WordPress plugin (through 0.2.0)
Easy Media Replace, a WordPress plugin for swapping media attachments, does not sanitise or escape the attachment title before outputting it inside an HTML attribute in the media library list view. Any user with Author privileges or higher can save an attachment title containing arbitrary web script, which then executes in the browser of an administrator or other higher-privileged user who opens the media library list view. A successful injection lets the attacker act within the victim's session, for example creating rogue admin accounts or altering site content. All WordPress sites running the plugin at version 0.2.0 or earlier are affected. Exploitation has not been reported in the wild; a public proof of concept exists, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.
What to do: WordPress administrators running Easy Media Replace 0.2.0 or earlier should update to the latest patched release as soon as one is available (no fixed version number is given in the current data). Until patching, deactivate the plugin or restrict media uploads and title editing to fully trusted users, and review existing attachment titles for injected script markup that would fire when an admin views the media list. Because a public proof of concept exists, treat any site with Author-role contributors on an unpatched version as exposed and check recent administrator activity for signs of session abuse.
| Easy Media Replace | through 0.2.0 (all releases up to and including 0.2.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.