CVE-2026-22519: WordPress MediaPress plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress allows Stored XSS.This issue affects MediaPress: from n/a through 1.6.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress mediapress allows Stored XSS.This issue affects MediaPress: from n/a through <= 1.6.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22519?
CVE-2026-22519 has a medium severity due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-22519?
To fix CVE-2026-22519, you should update the BuddyDev MediaPress plugin to version 1.6.3 or later.
What types of attacks can CVE-2026-22519 facilitate?
CVE-2026-22519 can facilitate stored XSS attacks, allowing attackers to inject malicious scripts into web pages.
Which versions of MediaPress are affected by CVE-2026-22519?
CVE-2026-22519 affects MediaPress versions up to and including 1.6.2.
Is user data at risk due to CVE-2026-22519?
Yes, user data can be at risk as stored XSS vulnerabilities may lead to unauthorized access and data theft.