CyberRota Analysis
AI-GeneratedThe Featured Image with URL plugin for WordPress versions prior to 1.0.6 is vulnerable due to inadequate sanitization and escaping of stored image attribute values, enabling users with Contributor roles to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability can impact any user viewing the affected posts, including those with higher privileges like Editors and Administrators, potentially leading to unauthorized actions or data exposure. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of exploitation.
Original NVD Description
The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.