Impact
The Auto Image Attributes From Filename With Bulk Updater plugin for WordPress suffers from a stored cross‑site scripting flaw caused by inadequate sanitization and escaping of attachment metadata. An attacker who can authenticate as an Author or higher can embed malicious JavaScript into attachment fields, causing the script to run when any user views a page that displays the affected attachment. The vulnerability is a classic input‑validation weakness (CWE‑79).
Affected Systems
WordPress sites that have installed the Auto Image Attributes From Filename With Bulk Updater plugin in any version up to and including 4.9 are affected.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score is currently unavailable, so no quantitative estimate of exploit likelihood is provided. The plugin is not listed in the CISA KEV catalog, which suggests no known active exploitation campaigns. Authenticating with Author level or higher is required, implying that the attack vector requires legitimate login credentials. Once an attacker injects code, the script will execute for any visitor to the affected page, potentially enabling data theft, session hijacking, or defacement.
OpenCVE Enrichment