Image Source Control Lite – Show Image Credits and Captions

Image Source Control Lite – Show Image Credits and Captions has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 5 are fixed as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (60%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Insertion Of Sensitive Information Into Log File.

Every one of the 5 issues recorded for Image Source Control Lite – Show Image Credits and Captions has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, one record each. Image Source Control Lite – Show Image Credits and Captions is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.6/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all Image Source Control Lite – Show Image Credits and Captions vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-4852

Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'Image Source' Field

Read the full analysis

Vulnerability Records

5 records
Image Source Control Lite – Show Image Credits and Captions banner
Latestv3.12.0

Image Source Control Lite – Show Image Credits and Captions

Thomas Maier

Author

Thomas Maier

4.6(42)
92/100
Last Updated
2026-08-26 (18d ago)
Active Installs
3,000+
Downloads
139,048
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2012-12-17 (14y ago)

Are you concerned about being held liable for violating copyright law, would like to start crediting owners or AI-generated images properly? Do you want to give back to photographers and illustrators by adding image credits, so they are rightfully attributed? Or are you a creator yourself and want to show information on the picture licenses for your image gallery under which publishers can use or purchase your work? Image Source Control is your go-to solution when it comes to handling copyright-protected photos and delete unused images. Documentation | Support | Premium Features | Delete Unused Images This level of personal and competent support deserves more than just five stars. Highly recommended! ⭐⭐⭐⭐⭐ by eunde Image Credit layouts Choose between different credit displays: List all image sources below the content of a specific page or place the list manually Show an image caption overlay above or below the image Embed a complete image credit list with thumbnails on your website Label AI-generated images Mark AI-generated images with a label that indicates the image was created by artificial intelligence. Following the EU AI act Available icons: AI, AI-generated, AI-manipulated Show only the icon or add a description text to it in the image source field Frontend Features Display image credits in the content, for image galleries, images added by shortcodes, and featured images … see more listed under Premium features below Define the layout and position of the caption overlay Show the image source fully, or only on click or mouseover Attach the Per-page list automatically, by using a shortcode, or with a PHP function Display image sources on archive pages Link to the copyright holder and include a link to the image license Add the EU AI label that marks an image as AI-generated Backend Features Add credits for any image file uploaded to the Media library Dedicated image source fields for the following blocks: Image, Cover Image, Featured Image, Media & Text Quickly assign a centrally defined source to any image and choose three options: hide image sources for these images, show a specific source (e.g., your name), or the uploader’s name Warn about missing image sources Manage, display, and link available licenses Enable the features for any files in the media library or for images only Filter the media library list by images with or without sources, or only those using the standard source Featured Image Caption ISC Lite works for Featured Images. By default, you will see the image credits options in the media library and the featured image options in the block editor. The featured image caption shows in the Per-page list with all other image sources on the page. Check out the premium features to display the image caption overlay for featured images. Premium Features Check out all features of Image Source Control. The Indexer looks for all images in all published content in one go List credits for images outside the content Add multiple links to the source string Manage image credits for images hosted outside the Media Library Handle images without file extensions Show image usage in the image details and the List view of the media library Bulk-edit image copyright information in the media library Preview image credits in the media library Show the standard picture credit for all images without a selected source Display IPTC copyright metadata in the backend and automatically as a standard source in the frontend Show the full text only after a click or on mouseover on the caption overlay Choose which data is displayed in the Global List List only images with a proper source in the Global List Show the Global List as a table or a simple list view Show image sources for Elementor background images, images in Kadence Blocks Galleries, and Kadence Related Content Carousel Developer options to show overlay captions for CSS background images Support for background images of the Group block Exclude certain images from showing the overlay by adding the isc-disable-overlay class Detect Unused Images (see below) Personal email support Extended compatibility with Elementor, Avada, WP Bakery, Divi, Fusion Builder, Flatsome UX Builder, and other page builders themes like Soledad and Kadence (including Kadence Blocks, Kadence Theme Kit Pro, Kadence Shop Kit Pro, and Kadence Related Content Carousel), as well as with plugins like Advanced Custom Fields, WPML, Lightbox Gallery, Newsletter plugin, and JetEngine. See Pricing. Unused Images Premium media cleaner features to remove unused images safely. Go to Media > Unused Images to see and remove unused images Run the Content Scan to find actually used images in the frontend Run the Database Scan to find references to images outside the content, like in meta data or options Bulk delete unused images Check either all images and pages, or only new or changed ones Works for pages behind a login (e.g., membership sites or maintenance mode) Filter the list by various states Ignore certain images from being listed as unused Constantly extended support for finding used and unused images in plugins and page builders, e.g., Elementor, Divi, WP Bakery, WP User Meta, WooCommerce, Kadence, and the Newsletter Plugin. See Pricing. Media Trash Move images to the trash instead of directly deleting them permanently. This eases the test if a deleted image was actually unused and allows for easy recovery if it was not. Enabled the module in the settings Media Trash has its own menu under Media > Media Trash Clear the media trash in bulk Recover trashed images with one click See Pricing. Btw., Image Source Control is a suitable alternative to the discontinued or closed plugins Image Credits, Credit Tracker, or FSM Custom Featured Image Caption. Instructions Take a look at the Image Source Control Documentation. Find a list of missing images sources and other debug tools under Media > Image sources You can choose to display image sources below the post content or as a small caption overlay above your images. Just visit the settings page of the plugin to enable those options. Manually included image sources on pages/posts You can add the Per-page list manually to pages or posts via the shortcode [isc_list] in your content editor or a text widget. Use [isc_list id="123"] to show the list of any post or page. Use the PHP code <?php if( function_exists('isc_list') ) { isc_list(); } ?> within your template files. List all image sources You can add a paginated list with ALL attachments and sources attached to posts and pages—the Global list—using the shortcode [isc_list_all]. Use [isc_list_all per_page="25"] to show only a limited number of images per page. Use [isc_list_all included="all"] to show all attachments in the list, including those not explicitly attached to a post. The plugin searches your post content and thumbnail for images (attachments) and lists them if you included at least the image source or marked it to use the default image source. Remove “nofollow” from all source links In order to remove “nofollow” from source links, follow the instructions in our documentation.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C