Description
The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.
Published: 2026-09-11
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS causing arbitrary script execution in browsers
Action: Patch Plugin
AI Analysis

Impact

The plugin fails to sanitize or escape an image attribute value before rendering it, enabling a stored cross‑site scripting attack. A user with a Contributor role can embed malicious script in the image’s alt text, which will run in the browser of any visitor to the affected post, including privileged Editors and Administrators. The stored nature of the flaw means the attack is persistent and does not require a separate session, exposing the site to credential theft, defacement, or knock‑on attacks.

Affected Systems

WordPress "Featured Image with URL" plugin versions earlier than 1.0.6. Any installation of this plugin that allows Contributors to edit posts is affected.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, while EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the flaw is highly exploitable: it requires only the ability to edit a post, a rights level that is commonly available to many users. With no mitigating controls disclosed by the vendor, the risk remains high and an attacker can easily craft a payload that executes in a victim’s browser.

Generated by OpenCVE AI on September 11, 2026 at 14:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Featured Image with URL to version 1.0.6 or later.
  • If an upgrade is not feasible, disable the plugin or remove stored alt text from existing posts.
  • Restrict the Contributor role so that users cannot edit image attributes or set post content to prevent insertion of malicious data.

Generated by OpenCVE AI on September 11, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.
Title Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:08:33.712Z

Reserved: 2026-09-08T11:42:54.536Z

Link: CVE-2026-86780

cve-icon Vulnrichment

Updated: 2026-09-11T10:01:30.852Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:47.450

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-86780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T14:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')