CVE-2026-1391

MEDIUM

Vzaar Media Management <= 1.2 - Unauthenticated Reflected Cross-Site Scripting via PHP_SELF Variable

Title source: llm
STIX 2.1

Description

The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on the $_SERVER['PHP_SELF'] variable. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
mamunreza/Vzaar Media Management < 1.2
Published Jan 28, 2026
Tracked Since Feb 18, 2026