Junglewise Threat Intelligence

CVE-2026-57431: Mervin Praison Featured Image XSS in WordPress plugin

CVE-2026-57431 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Executive brief

The Featured Image plugin for WordPress is vulnerable to a security flaw that allows users with 'Author' level permissions to inject malicious scripts into the website. If an administrator or another visitor views the affected content, these scripts could execute, potentially leading to unauthorized actions, website redirects, or the theft of sensitive session information. This issue affects versions 2.1 and earlier and has been resolved in version 2.2.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Mervin Praison Featured Image plugin for WordPress (versions <= 2.1). The flaw is categorized as CWE-79 (Improper Neutralization of Input During Web Page Generation) and stems from insufficient input sanitization and output encoding. An attacker with 'Author' privileges can inject malicious JavaScript payloads that execute in the context of a victim's browser (typically a site administrator) when they interact with the affected page. The vulnerability requires user interaction and is mitigated by upgrading to version 2.2.

Affected products

  • Mervin Praison Featured Image <= 2.1

Timeline

  • 2025-10-11: other: Reported by Muhammad Yudha - DJ
  • 2026-06-25: advisory: Published by Patchstack
  • 2026-06-26: disclosed: NVD Published Date

References