PT-2026-1764 · WordPress+2 · Bialty - Bulk Image Alt Text (Alt Tag+2

Published

2026-01-09

·

Updated

2026-01-09

·

CVE-2025-15019

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress versions up to and including 2.2.1
Description The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is susceptible to Stored Cross-Site Scripting. The issue is due to insufficient input sanitization and output escaping in the bialty cs alt post meta. Authenticated attackers with contributor level access or higher can inject arbitrary web scripts into pages. These scripts will execute when an administrator accesses the post editor.
Recommendations Update the BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress to a version later than 2.2.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-15019

Affected Products

Bialty - Bulk Image Alt Text (Alt Tag
Woocommerce
Yoast Seo