WordPress security by component
Featured Image with URL
Featured Image with URL (featured-image-with-url) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.8.
Plugin slug:
featured-image-with-urlLatest vulnerability
CVE-2026-86780: Featured Image with URL permits contributor stored XSS
Featured Image with URL before 1.0.6 stores an attacker-controlled image attribute without adequate sanitization and later outputs it without context-appropriate escaping. A Contributor can inject script that executes for anyone viewing the affected post, including Editors and Administrators. The authoritative export does not identify the attribute, save action, or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-86780
Featured Image with URL permits contributor stored XSS
Featured Image with URL before 1.0.6 stores an attacker-controlled image attribute without adequate sanitization and later outputs it without context-appropriate escaping. A Contributor can inject script that executes for anyone viewing the affected post, including Editors and Administrators. The authoritative export does not identify the attribute, save action, or rendering function.
|
1.0.6 |
CVE6.8
NVDPending
|