MEDIUM
Easy Media Replace
CVE published 2026-08-19
CVE-2026-15253
The Easy Media Replace WordPress plugin through 0.2.0 is vulnerable to cross-site scripting (XSS) attacks due to improper sanitization and escaping of attachment titles in the media library list view. This allows users with the Author role and above to inject arbitrary web scripts executed in the browser of higher-privileged users viewing the media library. Administrators and users of the plugin should re [truncated]