📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Cybersecurity Technology LOW 1h Global vulnerability Data Centers and Critical Infrastructure CRITICAL 2h Global general Enterprise Security and Governance HIGH 2h Global phishing General Public / Multiple Sectors HIGH 2h Global vulnerability Windows Systems and Enterprise IT CRITICAL 2h Global vulnerability Information Technology HIGH 2h Global general Information Technology and Cybersecurity HIGH 3h Global vulnerability Cybersecurity Services HIGH 3h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Enterprise Software and Cloud Services HIGH 4h Global general Cybersecurity Technology LOW 1h Global vulnerability Data Centers and Critical Infrastructure CRITICAL 2h Global general Enterprise Security and Governance HIGH 2h Global phishing General Public / Multiple Sectors HIGH 2h Global vulnerability Windows Systems and Enterprise IT CRITICAL 2h Global vulnerability Information Technology HIGH 2h Global general Information Technology and Cybersecurity HIGH 3h Global vulnerability Cybersecurity Services HIGH 3h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Enterprise Software and Cloud Services HIGH 4h Global general Cybersecurity Technology LOW 1h Global vulnerability Data Centers and Critical Infrastructure CRITICAL 2h Global general Enterprise Security and Governance HIGH 2h Global phishing General Public / Multiple Sectors HIGH 2h Global vulnerability Windows Systems and Enterprise IT CRITICAL 2h Global vulnerability Information Technology HIGH 2h Global general Information Technology and Cybersecurity HIGH 3h Global vulnerability Cybersecurity Services HIGH 3h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Enterprise Software and Cloud Services HIGH 4h
Vulnerabilities

CVE-2026-2382

Medium
CWE-79 — Weakness Type
Published: Jun 2, 2026  ·  Modified: Jun 5, 2026  ·  Source: NVD
CVSS v3
6.4
🔗 NVD Official
📄 Description (English)

The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page.

🤖 AI Executive Summary

The FPW Category Thumbnails WordPress plugin contains a Stored Cross-Site Scripting (XSS) vulnerability in versions up to 1.9.5 affecting the 'fpw_fs_get_file' AJAX action. Authenticated attackers with Subscriber-level access can inject malicious scripts that execute when administrators access plugin settings, potentially leading to account compromise and unauthorized administrative actions. No patch is currently available, requiring immediate mitigation through plugin disabling or removal.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 3, 2026 09:00
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using WordPress with the FPW Category Thumbnails plugin face significant risk, particularly in the government, banking, and healthcare sectors where WordPress is increasingly deployed for content management. Government agencies (under NCA oversight) and SAMA-regulated financial institutions are at elevated risk due to the potential for administrative account compromise. E-commerce platforms and media organizations in Saudi Arabia using this plugin could experience data breaches, unauthorized content modification, and compliance violations. The vulnerability is particularly dangerous in multi-user WordPress environments common in Saudi enterprises where Subscriber-level accounts are widely distributed.
🏢 Affected Saudi Sectors
Government (NCA-regulated agencies) Banking and Financial Services (SAMA-regulated) Healthcare E-commerce and Retail Media and Publishing Education Telecommunications
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all WordPress installations in your organization to identify if FPW Category Thumbnails plugin is installed and active
2. If installed, immediately disable and deactivate the plugin through WordPress admin panel
3. Review WordPress user accounts with Subscriber-level access and above for suspicious activity in the past 30 days
4. Check WordPress admin access logs for unauthorized logins or settings page access

PATCHING GUIDANCE:
1. Do not update to a patched version as none is currently available
2. Remove the plugin entirely: Navigate to Plugins > Installed Plugins > FPW Category Thumbnails > Delete
3. If plugin functionality is critical, evaluate alternative plugins with active security maintenance
4. Contact plugin developer for security update timeline

COMPENSATING CONTROLS:
1. Implement Web Application Firewall (WAF) rules to block AJAX requests to 'fpw_fs_get_file' action
2. Restrict Subscriber-level account creation and audit existing accounts
3. Implement Content Security Policy (CSP) headers to prevent inline script execution
4. Enable WordPress security plugins (Wordfence, Sucuri) with XSS detection rules
5. Implement strict input validation at WAF level for 'id' parameter in AJAX requests

DETECTION RULES:
1. Monitor WordPress logs for AJAX requests to 'fpw_fs_get_file' with suspicious 'id' parameter values containing script tags or encoded payloads
2. Alert on any modifications to plugin settings pages by non-administrative users
3. Monitor for stored XSS patterns in WordPress post/page metadata
4. Track admin page access logs for unusual timing or source IPs
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بتدقيق جميع تثبيتات WordPress في مؤسستك لتحديد ما إذا كان مكون FPW Category Thumbnails مثبتاً ونشطاً
2. إذا كان مثبتاً، قم بتعطيل وإلغاء تنشيط المكون فوراً من خلال لوحة إدارة WordPress
3. راجع حسابات مستخدمي WordPress بمستوى المشترك وما فوقه للنشاط المريب في آخر 30 يوماً
4. تحقق من سجلات وصول مسؤول WordPress للدخول غير المصرح به أو وصول صفحة الإعدادات

إرشادات التصحيح:
1. لا تحدث إلى نسخة مصححة لأنه لا توجد حالياً
2. أزل المكون بالكامل: انتقل إلى المكونات > المكونات المثبتة > FPW Category Thumbnails > حذف
3. إذا كانت وظيفة المكون حرجة، قيّم المكونات البديلة ذات الصيانة الأمنية النشطة
4. اتصل بمطور المكون للحصول على جدول زمني لتحديث الأمان

الضوابط التعويضية:
1. تنفيذ قواعد جدار حماية تطبيقات الويب (WAF) لحظر طلبات AJAX إلى إجراء 'fpw_fs_get_file'
2. تقييد إنشاء حسابات المشترك وتدقيق الحسابات الموجودة
3. تنفيذ رؤوس سياسة أمان المحتوى (CSP) لمنع تنفيذ النصوص البرمجية المضمنة
4. تفعيل مكونات أمان WordPress (Wordfence, Sucuri) مع قواعد كشف XSS
5. تنفيذ التحقق من الإدخال الصارم على مستوى WAF لمعامل 'id' في طلبات AJAX

قواعد الكشف:
1. مراقبة سجلات WordPress لطلبات AJAX إلى 'fpw_fs_get_file' بقيم معامل 'id' مريبة تحتوي على علامات نصية أو حمولات مشفرة
2. التنبيه على أي تعديلات على صفحات إعدادات المكون من قبل المستخدمين غير الإداريين
3. مراقبة أنماط XSS المخزنة في بيانات وصفية لمنشورات/صفحات WordPress
4. تتبع سجلات وصول صفحة المسؤول للأنشطة غير العادية أو عناوين IP المصدر
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security requirements for supplier relationships ECC 2024 A.14.2.5 - Addressing information security in supplier agreements ECC 2024 A.5.23 - Access control and authentication mechanisms ECC 2024 A.6.1 - Cryptography and secure coding practices
🔵 SAMA CSF
SAMA CSF 1.1 - Governance and Risk Management SAMA CSF 2.1 - Asset Management and Protection SAMA CSF 3.2 - Access Control and Authentication SAMA CSF 4.1 - Detection and Analysis of security events
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access control ISO 27001:2022 A.5.16 - Authentication ISO 27001:2022 A.8.22 - Web application security ISO 27001:2022 A.8.24 - Protection against malware
🟣 PCI DSS v4.0.1
PCI DSS 6.5.7 - Cross-site scripting (XSS) prevention PCI DSS 6.5.1 - Injection flaws prevention PCI DSS 7.1 - Limit access to system components by business need to know
📊 CVSS Score
6.4
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.4
CWECWE-79
EPSS0.03%
Exploit No
Patch ✗ No
Published 2026-06-02
Source Feed nvd
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-79
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.