SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86780

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Featured Image with URL plugin for WordPress versions prior to 1.0.6 is vulnerable due to inadequate sanitization and escaping of stored image attribute values, enabling users with Contributor roles to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability can impact any user viewing the affected posts, including those with higher privileges like Editors and Administrators, potentially leading to unauthorized actions or data exposure. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of exploitation.

CVE
CVE-2026-86780
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress

Original NVD Description

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.