CVE-2026-42643: WordPress Image Widget plugin <= 4.4.11 - Cross Site Scripting (XSS) vulnerability
Published Apr 29, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a through <= 4.4.11.
Affected Software
1 affected component
Stellarwp Image Widget<=4.4.11
Event History
Apr 29, 2026
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42643?
CVE-2026-42643 is classified as a critical vulnerability due to its potential for allowing stored XSS attacks.
2
How do I fix CVE-2026-42643?
To fix CVE-2026-42643, upgrade the StellarWP Image Widget plugin to the latest version beyond 4.4.11.
3
What versions of the StellarWP Image Widget are affected by CVE-2026-42643?
CVE-2026-42643 affects StellarWP Image Widget versions up to and including 4.4.11.
4
What type of vulnerability is CVE-2026-42643?
CVE-2026-42643 is a Cross-Site Scripting (XSS) vulnerability, specifically a stored XSS issue.
5
Can CVE-2026-42643 be exploited remotely?
Yes, CVE-2026-42643 can be exploited remotely by injecting malicious scripts into the input fields of the affected plugin.