Cross-Site Scripting Vulnerability in StellarWP Image Widget
CVE-2026-42643

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 April 2026

What is CVE-2026-42643?

The StellarWP Image Widget contains a vulnerability that allows for Stored Cross-Site Scripting (XSS). This occurs due to improper handling of user input when generating web pages. Attackers can exploit this flaw to inject malicious scripts into web applications, potentially leading to data theft, session hijacking, and unauthorized actions on behalf of users. Websites utilizing versions of the plugin prior to 4.4.11 are particularly at risk.

Affected Version(s)

Image Widget 0 <= 4.4.11

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut | Patchstack Bug Bounty Program
.