CVE-2026-86780
Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.
| Vendor | unknown |
| Product | featured image with url |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown featured image with url
Be the first to know when new medium vulnerabilities affecting unknown featured image with url are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Featured Image with URL
0 < 1.0.6
References
Credits
Artus KG WPScan