CVE-2025-12019
⚪ Do wiadomości
Wtyczka Featured Image dla WordPressa ma podatność na XSS, co pozwala na wstrzyknięcie skryptów.
CVSS
4.4
EPSS
0.5%
Exploit
poc
Vendor
mer.vin
Opis źródłowy (NVD)
The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
exploit xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2025-11-11 04:15:45 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 21:10:00 UTC |
Referencje
- https://github.com/zast-ai/vulnerability-reports/blob/main/wordpress/plugin/featured-image/stored-xss.md ([email protected]) [Exploit, Third Party Advisory]
- https://plugins.trac.wordpress.org/browser/featured-image/tags/2.1/featured-image.php#L26 ([email protected]) [URL Repurposed]
- https://plugins.trac.wordpress.org/browser/featured-image/tags/2.1/featured-image.php#L35 ([email protected]) [URL Repurposed]
- https://plugins.trac.wordpress.org/browser/featured-image/tags/2.1/featured-image.php#L65 ([email protected]) [URL Repurposed]
- https://plugins.trac.wordpress.org/changeset/3392100/ ([email protected])
- https://wordpress.org/plugins/featured-image/ ([email protected]) [Release Notes]
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fa16605a-12bd-48a8-b9a9-db53bf3c2c39?source=cve ([email protected]) [Third Party Advisory]