CVE-2025-28918

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in A. Jones Featured Image Thumbnail Grid allows Stored XSS. This issue affects Featured Image Thumbnail Grid: from n/a through 6.6.1.

More information : https://patchstack.com/database/wordpress/plugin/thumbnail-grid/vulnerability/wordpress-featured-image-thumbnail-grid-plugin-6-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve