Junglewise Threat Intelligence

CVE-2026-39693: fesomia FSM Custom Featured Image Caption DOM XSS

CVE-2026-39693 · Severity: medium · CVSS 5.9 · Published 2026-04-08

Executive brief

The FSM Custom Featured Image Caption plugin for WordPress, which allows users to add custom captions to featured images, is vulnerable to a security flaw. An attacker with high-level permissions (such as an Author) can inject malicious scripts into the website. If another user views the affected page, these scripts could lead to unauthorized actions, website redirects, or the display of malicious content.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the fesomia FSM Custom Featured Image Caption plugin for WordPress (versions <= 1.25.1). The flaw stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Author' or higher privileges can inject malicious scripts that execute in the context of a victim's browser when they interact with the affected page. Successful exploitation requires user interaction from a privileged user. As of the advisory date, no official patch has been released.

Affected products

  • fesomia FSM Custom Featured Image Caption <= 1.25.1

Timeline

  • 2026-01-26: other: Vulnerability reported by Nabil Irawan
  • 2026-02-25: disclosed: Advisory published by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References