📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Enterprise Security, Software Development CRITICAL 57m Global vulnerability Software Development, Artificial Intelligence HIGH 1h Global apt Defense and Military CRITICAL 1h Global vulnerability Networking, Software, Infrastructure HIGH 1h Global phishing Information Technology HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Multiple sectors CRITICAL 2h Global general Cybersecurity LOW 2h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Technology/Software CRITICAL 3h Global vulnerability Enterprise Security, Software Development CRITICAL 57m Global vulnerability Software Development, Artificial Intelligence HIGH 1h Global apt Defense and Military CRITICAL 1h Global vulnerability Networking, Software, Infrastructure HIGH 1h Global phishing Information Technology HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Multiple sectors CRITICAL 2h Global general Cybersecurity LOW 2h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Technology/Software CRITICAL 3h Global vulnerability Enterprise Security, Software Development CRITICAL 57m Global vulnerability Software Development, Artificial Intelligence HIGH 1h Global apt Defense and Military CRITICAL 1h Global vulnerability Networking, Software, Infrastructure HIGH 1h Global phishing Information Technology HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Multiple sectors CRITICAL 2h Global general Cybersecurity LOW 2h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Technology/Software CRITICAL 3h
Vulnerabilities

CVE-2026-3722

Medium
CWE-79 — Weakness Type
Published: Jun 2, 2026  ·  Modified: Jun 5, 2026  ·  Source: NVD
CVSS v3
6.4
🔗 NVD Official
📄 Description (English)

The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

🤖 AI Executive Summary

A Stored XSS vulnerability exists in the Auto Image Attributes From Filename With Bulk Updater WordPress plugin (versions ≤4.9) allowing authenticated users with Author-level access to inject malicious scripts into attachment metadata. The vulnerability has a CVSS score of 6.4 (medium) and currently lacks a patch. This poses a significant risk to WordPress-based websites in Saudi Arabia, particularly those managing content through multiple authors.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 2, 2026 18:36
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi organizations using WordPress for content management, including: Government agencies and ministries managing public-facing websites, Media and publishing companies, Educational institutions (universities and schools), E-commerce platforms, and Corporate websites with multiple content authors. The risk is elevated in organizations with less stringent access controls and those managing sensitive information through WordPress. ARAMCO, STC, and other large enterprises using WordPress for internal or external communications are at moderate risk if proper access controls are not enforced.
🏢 Affected Saudi Sectors
Government and Public Administration Media and Publishing Education (Universities and Schools) E-commerce and Retail Corporate Communications Healthcare (if using WordPress for patient portals) Non-Profit Organizations
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all users with Author-level access and above — review their recent activities and uploaded attachments
2. Disable the Auto Image Attributes From Filename With Bulk Updater plugin immediately until a patch is available
3. Search WordPress database for suspicious scripts in attachment metadata using: SELECT * FROM wp_postmeta WHERE meta_key LIKE '%attachment%' AND meta_value LIKE '%<script%'
4. Review page access logs for unauthorized modifications to attachment metadata

COMPENSATING CONTROLS (if plugin removal is not feasible):
5. Restrict Author-level access to only trusted, vetted users
6. Implement Web Application Firewall (WAF) rules to detect and block XSS payloads in attachment metadata
7. Enable WordPress security plugins (Wordfence, Sucuri) with XSS detection capabilities
8. Implement Content Security Policy (CSP) headers to mitigate XSS execution

DETECTION:
9. Monitor wp-admin logs for attachment metadata modifications
10. Deploy YARA rules to detect common XSS patterns in WordPress database exports
11. Implement file integrity monitoring on wp-content/uploads directory
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع المستخدمين بمستوى Author وما فوقه - مراجعة أنشطتهم الأخيرة والملفات المرفوعة
2. تعطيل إضافة Auto Image Attributes From Filename With Bulk Updater فوراً حتى يتوفر تصحيح
3. البحث في قاعدة بيانات WordPress عن النصوص البرمجية المريبة في بيانات المرفقات
4. مراجعة سجلات الوصول للصفحات للتعديلات غير المصرح بها على بيانات المرفقات

الضوابط البديلة (إذا لم يكن من الممكن إزالة الإضافة):
5. تقييد وصول Author-level فقط للمستخدمين الموثوقين والمتحقق منهم
6. تنفيذ قواعد جدار حماية تطبيقات الويب (WAF) للكشف عن حمولات XSS وحجبها
7. تفعيل إضافات أمان WordPress (Wordfence, Sucuri) مع قدرات كشف XSS
8. تنفيذ رؤوس Content Security Policy (CSP) للتخفيف من تنفيذ XSS

الكشف:
9. مراقبة سجلات wp-admin لتعديلات بيانات المرفقات
10. نشر قواعد YARA للكشف عن أنماط XSS الشائعة في تصديرات قاعدة بيانات WordPress
11. تنفيذ مراقبة سلامة الملفات على دليل wp-content/uploads
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.6.1.1 - User access management and authentication A.6.2.1 - User access rights review A.8.2.1 - Classification of information A.12.2.1 - Change management procedures A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
ID.AM-2 - Software inventory and asset management PR.AC-1 - Access control policy and procedures PR.AC-4 - Access rights and privileges management PR.DS-2 - Data security and protection DE.CM-8 - Vulnerability scanning and management RS.MI-2 - Incident response and containment
🟡 ISO 27001:2022
A.5.1.1 - Information security policies A.6.1.1 - User access management A.6.2.1 - User access rights review A.8.2.3 - Segregation of duties A.12.2.1 - Change management A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy
🟣 PCI DSS v4.0.1
Requirement 1.1 - Firewall configuration standards Requirement 6.2 - Security patches and updates Requirement 6.5.7 - Cross-site scripting prevention Requirement 7.1 - Access control implementation
📊 CVSS Score
6.4
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.4
CWECWE-79
EPSS0.03%
Exploit No
Patch ✗ No
Published 2026-06-02
Source Feed nvd
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-79
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.