Impact
The plugin fails to sanitize or escape an image attribute value before rendering it, enabling a stored cross‑site scripting attack. A user with a Contributor role can embed malicious script in the image’s alt text, which will run in the browser of any visitor to the affected post, including privileged Editors and Administrators. The stored nature of the flaw means the attack is persistent and does not require a separate session, exposing the site to credential theft, defacement, or knock‑on attacks.
Affected Systems
WordPress "Featured Image with URL" plugin versions earlier than 1.0.6. Any installation of this plugin that allows Contributors to edit posts is affected.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the flaw is highly exploitable: it requires only the ability to edit a post, a rights level that is commonly available to many users. With no mitigating controls disclosed by the vendor, the risk remains high and an attacker can easily craft a payload that executes in a victim’s browser.
OpenCVE Enrichment