CVE-2026-42643
EUVD-2026-2621429.04.2026, 12:16
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a through <= 4.4.11.Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| stellarwp | image_widget | 𝑥 ≤ 4.4.11 | CNA |