ZeroHour

CVE-2026-15253

PoC niche

Stored XSS in Easy Media Replace WordPress plugin (through 0.2.0)

CVSS 3.1
6.8 medium
EPSS
<1%p22
Published
()
Modified
AI analysis

Easy Media Replace, a WordPress plugin for swapping media attachments, does not sanitise or escape the attachment title before outputting it inside an HTML attribute in the media library list view. Any user with Author privileges or higher can save an attachment title containing arbitrary web script, which then executes in the browser of an administrator or other higher-privileged user who opens the media library list view. A successful injection lets the attacker act within the victim's session, for example creating rogue admin accounts or altering site content. All WordPress sites running the plugin at version 0.2.0 or earlier are affected. Exploitation has not been reported in the wild; a public proof of concept exists, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.

What to do: WordPress administrators running Easy Media Replace 0.2.0 or earlier should update to the latest patched release as soon as one is available (no fixed version number is given in the current data). Until patching, deactivate the plugin or restrict media uploads and title editing to fully trusted users, and review existing attachment titles for injected script markup that would fire when an admin views the media list. Because a public proof of concept exists, treat any site with Author-role contributors on an unpatched version as exposed and check recent administrator activity for signs of session abuse.

Affected
Easy Media Replacethrough 0.2.0 (all releases up to and including 0.2.0)
Estimated exposure
nichelikely a few hundred to a few thousand sites (estimate; no published active-install count is available in the data) — No active-install counts or scan telemetry for this plugin are provided in the available sources, so the estimate rests on the plugin's early version (0.2.0) and its narrow media-replacement use case, which typically indicate a small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.