Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brechtvds
Brechtvds easy Image Collage Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brechtvds
Brechtvds easy Image Collage Wordpress Wordpress wordpress |
Wed, 10 Jun 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the data is stored via update_post_meta() rather than wp_insert_post() post content, WordPress's unfiltered_html restriction does not apply, meaning Authors cannot be blocked from this attack path by capability controls alone. | |
| Title | Easy Image Collage <= 1.13.6 - Authenticated (Author+) Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-10T16:32:03.865Z
Reserved: 2026-05-19T14:53:59.845Z
Link: CVE-2026-9019
Updated: 2026-06-10T16:27:48.278Z
Status : Received
Published: 2026-06-10T08:16:25.937
Modified: 2026-06-10T08:16:25.937
Link: CVE-2026-9019
No data.
OpenCVE Enrichment
Updated: 2026-06-10T11:21:12Z