CVE-2026-1298 | Easy Replace Image Plugin up to 3.5.2 on WordPress image_replacement_from_url authorization
A vulnerability categorized as problematic has been discovered in Easy Replace Image Plugin up to 3.5.2 on WordPress. Impacted is the function image_replacement_from_url. Such manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-1298. The attack can be executed remotely. There is not any exploit available.