Cross Site Scripting Vulnerability in Featured Image from URL by WordPress
CVE-2026-73340

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73340?

A Cross Site Scripting (XSS) vulnerability exists in the Featured Image from URL plugin for WordPress that affects versions up to 5.3.3. This flaw allows malicious users to inject arbitrary JavaScript code into web applications, potentially compromising the security of unsuspecting users. It emphasizes the importance of keeping your plugins updated to the latest versions to mitigate such vulnerabilities.

Affected Version(s)

Featured Image from URL <= 5.3.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

luc | Patchstack Bug Bounty Program
.