Missing Authorization in Easy Replace Image Plugin for WordPress
CVE-2026-1298
4.3MEDIUM
What is CVE-2026-1298?
The Easy Replace Image plugin for WordPress suffers from a Missing Authorization vulnerability due to inadequate capability checks in the image_replacement_from_url function linked to the eri_from_url AJAX action. This flaw allows authenticated users with Contributor-level access and higher to replace existing image attachments on the website with external images, posing risks of site defacement, phishing attacks, and content manipulation.
Affected Version(s)
Easy Replace Image 0 <= 3.5.2