CVE · Medium

CVE-2026-73340 — Featured Image from URL (FIFU) [featured-image-from-url] < 6.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-73340 Featured Image from URL (FIFU) [featured-image-from-url] < 6.0.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 6.0.0 6.0.0 2026-08-12

CVE-2026-73340

A vulnerability exists in the Featured Image from URL plugin for WordPress, specifically in versions up to and including 5.3.3, which allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into web pages. This occurs due to inadequate input validation and output protection, enabling attackers to embed arbitrary code that will execute when accessed by other users. As a result, attackers can potentially exploit this vulnerability to inject malicious scripts into sensitive areas of the website.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.