Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress mediapress allows Stored XSS.This issue affects MediaPress: from n/a through <= 1.6.2.
Published: 2026-01-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

Improper neutralization of user input in BuddyDev MediaPress allows attackers to store malicious scripts that are later executed in web browsers accessing the affected WordPress site. This stored XSS can lead to credential theft, session hijacking, defacement or arbitrary code execution from the perspective of the victim’s browser. The flaw resides in how content submitted through the plugin is rendered without adequate sanitization.

Affected Systems

WordPress installations that have installed the MediaPress plugin version 1.6.2 or earlier are affected. Any site using those versions without a later patch is vulnerable.

Risk and Exploitability

The lead‑time to exploit this flaw requires the attacker to be able to submit or edit content via the MediaPress interface, which typically means having write or administrative privileges on the site. The probability of exploitation is very low (EPSS < 1 %) and the vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploits. Nevertheless, because the flaw permits arbitrary script execution in a user’s browser, it poses a significant confidentiality and integrity risk for any site user. Organizations should treat this as a medium‑to‑high risk until a patch is applied.

Generated by OpenCVE AI on April 16, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BuddyDev MediaPress to a version newer than 1.6.2 that includes the XSS fix.
  • Restrict content‑creation and plugin modification permissions to trusted administrators only.
  • Implement server‑side input validation or a web application firewall rule that rejects payloads containing JavaScript and other harmful scripts.

Generated by OpenCVE AI on April 16, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress allows Stored XSS.This issue affects MediaPress: from n/a through 1.6.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress mediapress allows Stored XSS.This issue affects MediaPress: from n/a through <= 1.6.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 08 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress allows Stored XSS.This issue affects MediaPress: from n/a through 1.6.2.
Title WordPress MediaPress plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T16:00:40.746Z

Reserved: 2026-01-07T13:44:43.226Z

Link: CVE-2026-22519

cve-icon Vulnrichment

Updated: 2026-01-08T20:11:58.267Z

cve-icon NVD

Status : Deferred

Published: 2026-01-08T17:15:51.960

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-22519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T09:00:05Z

Weaknesses