Description
The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-01-06
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Update Plugin
AI Analysis

Impact

The MediaPress WordPress plugin is vulnerable to a stored cross‑site scripting flaw caused by insufficient sanitization and output escaping of user‑supplied parameters in the mpp‑uploader shortcode. This weakness falls under CWE‑79 and allows a logged‑in user with contributor or higher privileges to inject arbitrary JavaScript that becomes part of the gallery content and is later rendered in the browser when other visitors view the page.

Affected Systems

The vulnerability affects any WordPress site running MediaPress plugin version 1.6.1 or earlier. Users with contributor‑level access or higher can edit gallery pages and exploit the flaw. It is limited to installations that have the plugin active and have not applied the vendor’s latest patch.

Risk and Exploitability

The CVSS base score of 6.4 indicates moderate severity for authenticated users. The EPSS score of less than 1% reflects a very low probability of real‑world exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, because contributor roles are common on many sites, the potential for accidental or intentional compromise remains. An attacker would need to login, edit a gallery page, insert malicious shortcode, and then any visitor browsing that page would be subject to the injected script, enabling session hijacking, defacement, or phishing.

Generated by OpenCVE AI on April 22, 2026 at 00:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MediaPress to 1.6.2 or later to apply the vendor patch.
  • Revoke or reduce contributor permissions for editing gallery pages until the patch is deployed.
  • Configure the WordPress site or use a security plugin to strip or escape JavaScript from shortcode attributes as an interim mitigation.

Generated by OpenCVE AI on April 22, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 06 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title MediaPress <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:04:01.524Z

Reserved: 2025-12-11T20:41:24.721Z

Link: CVE-2025-14552

cve-icon Vulnrichment

Updated: 2026-01-06T14:25:08.715Z

cve-icon NVD

Status : Deferred

Published: 2026-01-06T10:15:48.117

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T00:15:03Z

Weaknesses