CVE-2026-1391 | Vzaar Media Management Plugin up to 1.2 on WordPress $_SERVER['PHP_SELF'] cross site scripting
A vulnerability described as problematic has been identified in Vzaar Media Management Plugin up to 1.2 on WordPress. Affected is an unknown function. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting.
This vulnerability is documented as CVE-2026-1391. The attack can be executed remotely. There is not any exploit available.