Featured Image
Featured Image has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Featured Image has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Featured Image is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2026-57431Featured Image <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Featured Image
Author
Mervin Praison
Add featured image to any part of the website, on each individual post/page. Very Easy to Implement. Provides you with a featured image shortcode [ featured-img ] , code and Featured Image widget. Paste the Code or the Shortcode on any part of the website. Very Easy to implement. Simple Shortcode Available Easy code Implementation inside loop and outside loop. Widge Avaliable Featured Image Caption WordPress Featured Image Documentation By Mervin Praison SEO Manager Version history version 2.2 Security: Fixed Stored Cross-Site Scripting (XSS) vulnerability (CVE-2025-12019) Fixed: Added missing global $post in caption function Improved: Enhanced security with proper output escaping version 2.1 global $post fix Version 2.0 Added Featured Image Caption Added Alt Text for images Fixed Bugs Version 1.0 Initial release version.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C