Sceawere

Vulnerability Detail

CVE-2026-73340UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Featured Image from URL XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
fifu.app
Product
Featured Image from URL
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T14:17:12.613Z",
  "pubdate": "2026-08-13T14:17:12.613Z",
  "executiveSummary": "This vulnerability is classified as a Cross-Site Scripting (XSS) security flaw affecting the Featured Image from URL plugin. The issue arises from insufficient sanitization and output encoding of user-supplied data handled by contributors within the plugin functionality.\nThe primary impact of this vulnerability is the execution of arbitrary JavaScript code in the context of an administrator's or other privileged user's browser session when interacting with the affected interface. This compromises the integrity of the application session and can lead to unauthorized actions performed on behalf of the victim.\nThe affected systems include installations running versions 5.3.3 and prior of the Featured Image from URL product. The risk implications involve potential privilege escalation, session hijacking, and administrative interface manipulation.\nAttacker capabilities require authenticated access with contributor-level privileges to interact with the vulnerable component. Exploitation requires the attacker to supply a crafted malicious payload containing executable script content within the input parameters processed by the plugin, which is subsequently rendered without adequate neutralization.",
  "technicalDetails": "The vulnerability exists within the Featured Image from URL plugin in versions <= 5.3.3, specifically in the component responsible for processing and displaying external image URLs and associated metadata.\nThe root cause of the vulnerability is improper input validation and lack of context-aware output encoding. The application accepts input from users with contributor privileges and reflects this data back into the Document Object Model (DOM) without sanitizing potentially dangerous HTML or JavaScript constructs.\nAuthentication and privilege requirements dictate that the threat actor must possess valid credentials with contributor-level privileges to initiate the attack vector. The network exposure is standard web application accessibility via HTTP/HTTPS protocols.\nThe attack flow proceeds as follows: First, the authenticated contributor crafts an HTTP request containing a malicious payload—such as a script tag or an event handler (e.g., onload, onerror)—disguised as an image URL or associated parameter. Second, the vulnerable component processes the input and stores or reflects it within the administrative dashboard or management interface without applying proper escaping mechanisms. Third, when a privileged user, such as an administrator, views the affected post or interface containing the crafted entry, the malicious payload is rendered directly by the browser.\nThe payload behavior involves executing arbitrary JavaScript in the security context of the victim's session. This allows the script to interact with the Document Object Model, access session cookies if not protected by appropriate flags, perform unauthorized administrative actions, or inject further malicious functionality.\nPost-exploitation impact includes the potential creation of rogue administrative accounts, modification of site content, or pivoting to other backend functionalities accessible to the compromised session, thereby undermining the overall security posture of the web application."
}
CVE-2026-73340: Featured Image from URL XSS (MEDIUM Severity, CVSS: 6.5) - Sceawere