← WordPress Vulnerabilities
WordPress security by component

Featured Image with URL

Featured Image with URL (featured-image-with-url) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.8.

Plugin slug: featured-image-with-url

CVE-2026-86780: Featured Image with URL permits contributor stored XSS

Featured Image with URL before 1.0.6 stores an attacker-controlled image attribute without adequate sanitization and later outputs it without context-appropriate escaping. A Contributor can inject script that executes for anyone viewing the affected post, including Editors and Administrators. The authoritative export does not identify the attribute, save action, or rendering function.

PublishedSep 11, 2026
Known safe version1.0.6
Published vulnerabilities for featured-image-with-url
Safe version
Sep 11, 2026 CVE-2026-86780
Featured Image with URL permits contributor stored XSS
Featured Image with URL before 1.0.6 stores an attacker-controlled image attribute without adequate sanitization and later outputs it without context-appropriate escaping. A Contributor can inject script that executes for anyone viewing the affected post, including Editors and Administrators. The authoritative export does not identify the attribute, save action, or rendering function.
1.0.6
CVE6.8
NVDPending