Stored Cross-Site Scripting in Easy Author Image Plugin for WordPress
CVE-2026-1373

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 February 2026

What is CVE-2026-1373?

The Easy Author Image plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to exploit Stored Cross-Site Scripting (XSS). This occurs through the 'author_profile_picture_url' parameter, which lacks sufficient input sanitization and output escaping. As a result, attackers can inject arbitrary web scripts into the plugin, compromising the integrity of pages viewed by users. This vulnerability affects all versions of the plugin up to and including version 1.7, posing a significant risk to unsuspecting users who may visit the manipulated pages.

Affected Version(s)

Easy Author Image 0 <= 1.7

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan
.