Fifu
Fifu Featured Image From URL: vulnerabilidades y CVE
Fifu Featured Image From URL tiene 9 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-101147 | Alta (8.8) | — | — | 1 oct 2026 | The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole… |
| CVE-2026-73340 | Media (6.5) | 0.22% | — | 13 ago 2026 | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. |
| CVE-2025-10037 | Media (4.9) | 0.33% | — | 26 sept 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_featured_image() function in all versions up to, and including, 5.2.7 due to insufficient escaping… |
| CVE-2024-37516 | Media (6.3) | 0.42% | — | 1 nov 2024 | Missing Authorization vulnerability in fifu.App Featured Image from URL allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image from URL: from n/a through 4.8.2. |
| CVE-2024-37276 | Media (5.3) | 0.36% | — | 1 nov 2024 | Missing Authorization vulnerability in fifu.App Featured Image from URL allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image from URL: from n/a through 4.8.1. |
| CVE-2024-1496 | Media (5.4) | 0.43% | — | 29 feb 2024 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 due to insufficient input sanitization… |
| CVE-2023-6561 | Media (5.4) | 0.45% | — | 11 ene 2024 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up to, and including, 4.5.3 due to insufficient input sanitization and… |
| CVE-2022-2278 | Media (4.8) | 0.61% | — | 1 ago 2022 | The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting… |
| CVE-2022-2241 | Media (6.1) | 0.63% | — | 1 ago 2022 | The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.… |