CVE · Medium

CVE-2026-3722 — Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) [auto-image-attributes-from-filename-with-bulk-updater] < 4.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-3722 Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) [auto-image-attributes-from-filename-with-bulk-updater] < 4.9.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.9.1 4.9.1 2026-06-01

CVE-2026-3722

The Auto Image Attributes From Filename With Bulk Updater plugin for WordPress is susceptible to Stored Cross-Site Scripting until version 4.9, inclusive. Insufficient input sanitization and output escaping allow attackers with Author-level permissions or higher to inject malicious scripts into image metadata. These scripts can be executed whenever a user views the affected page, potentially leading to unauthorized actions on the site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.