The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators. | |
| Title | Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-11T06:00:08.841Z
Reserved: 2026-09-08T11:42:54.536Z
Link: CVE-2026-86780
No data.
Status : Received
Published: 2026-09-11T07:16:47.450
Modified: 2026-09-11T07:16:47.450
Link: CVE-2026-86780
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.