Junglewise Threat Intelligence

CVE-2026-3722: WordPress Auto Image Attributes From Filename Stored XSS in metadata

CVE-2026-3722 · Severity: medium · CVSS 6.4 · Published 2026-06-02

Vendors: Wordpress.

Executive brief

A WordPress plugin used for automating image SEO attributes is vulnerable to a security flaw that allows certain users to inject malicious scripts into the website. An attacker with Author-level permissions or higher could use this to run unauthorized code in the browsers of other users, including administrators, potentially leading to site takeover or data theft. This issue affects all versions of the plugin up to and including 4.9.

Technical details

The Auto Image Attributes From Filename With Bulk Updater plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on attachment metadata. Authenticated attackers with Author-level access or higher can exploit this by injecting arbitrary web scripts into image metadata fields. These scripts are then stored on the server and executed in the context of any user's browser who views the affected media library or associated pages. The vulnerability is present in all versions up to and including 4.9. Mitigation involves updating to a patched version if available or ensuring strict sanitization of image metadata.

Affected products

  • WordPress Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) Up to and including 4.9

Timeline

  • 2026-06-02: advisory: NVD publication date

References