What is CVE-2026-15253?
The Easy Media Replace WordPress plugin (up to version 0.2.0) does not sanitize and escape an attachment title before outputting it in an HTML attribute in the media library list view. This allows users with Author role and above to inject arbitrary web scripts that execute in a higher-privileged user's browser, leading to Stored XSS. It is recommended to update the plugin to the latest available version immediately.
Azərbaycanca: Easy Media Replace WordPress plaqini (0.2.0-ə qədər versiyalar) media kitabxanası siyahısında əlavə fayl başlığını HTML atributunda çıxarmazdan əvvəl sanitizə etmir. Bu, Author və daha yüksək roluna malik istifadəçilərə, daha yüksək səlahiyyətli istifadəçinin brauzerində icra olunan ixtiyari veb skriptlər (stored XSS) yeritməyə imkan yaradır. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Easy Media Replace plugin are affected by CVE-2026-15253?
This Stored XSS vulnerability affects all versions of the Easy Media Replace WordPress plugin up to version 0.2.0.
What minimum privilege level does an attacker need to exploit CVE-2026-15253?
An attacker needs to have at least the Author role to exploit this Stored XSS vulnerability and inject arbitrary web scripts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.