Impact
The vendor‑maintained plugin "Featured Image from URL" releases before version 5.3.3 allow malicious input to be stored and later rendered in the browser. The vulnerability is a classic stored cross‑site scripting flaw that can expose visitor browsers to arbitrary JavaScript. The flaw may lead to the theft of session cookies, account takeover, or defacement of sites where users view contributor‑generated image URLs.
Affected Systems
WordPress websites that have installed the Featured Image from URL plugin version 5.3.3 or earlier. Only the plugin itself is directly affected; no other WordPress components are listed as vulnerable.
Risk and Exploitability
With a CVSS score of 6.5 the flaw is considered moderate to high severity. The EPSS value is not available, so current exploitation likelihood cannot be quantified, and the vulnerability is not listed in the Centers for Disease Control and Prevention KEV catalog. The most probable attack path is through a contributor who can input a crafted image URL that travels through the plugin’s rendering logic and injects executable code into the page. Once executed, the script runs under the privileges of the logged‑in user or, in a worst case, any site visitor. Because the attack surface depends on the plugin's permission levels, sites that give contributor access should scrutinize the plugin’s input handling carefully.
OpenCVE Enrichment