Stored Cross-Site Scripting Vulnerability in Image Alt Text Manager Plugin for WordPress
CVE-2026-3350
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 March 2026
What is CVE-2026-3350?
The Image Alt Text Manager plugin for WordPress contains a vulnerability that allows authenticated attackers with Author-level access and above to carry out Stored Cross-Site Scripting (XSS) attacks. This vulnerability arises from inadequate input sanitization and output escaping when the plugin dynamically generates image alt and title attributes using a DOM parser. As a result, attackers can inject arbitrary web scripts into pages, which will execute whenever a user visits the crafted page, potentially compromising user data and site integrity.
Affected Version(s)
Image Alt Text Manager β Bulk & Dynamic Alt Tags For image SEO Optimization + AI 0 <= 1.8.2
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Itthidej Aramsri
Pattama Tangpoonponwiwat
Korn Dhampiban-udom