Through a CSRF vulnerability discovered in the Featured Image from URL plugin (version <= 3.9.9), any configuration can be updated to XSS.
Update to the latest version (at least 4.0.0) available from the WordPress Featured Image from URL plugin.
脆弱性情報を受け取る