Stored Cross-Site Scripting in Easy Author Image Plugin for WordPress
CVE-2026-1373
6.4MEDIUM
What is CVE-2026-1373?
The Easy Author Image plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to exploit Stored Cross-Site Scripting (XSS). This occurs through the 'author_profile_picture_url' parameter, which lacks sufficient input sanitization and output escaping. As a result, attackers can inject arbitrary web scripts into the plugin, compromising the integrity of pages viewed by users. This vulnerability affects all versions of the plugin up to and including version 1.7, posing a significant risk to unsuspecting users who may visit the manipulated pages.
Affected Version(s)
Easy Author Image 0 <= 1.7