Extension WordPress
Vulnérabilités Featured Image from URL (FIFU)
Cette page rassemble les failles publiées pour Featured Image from URL (FIFU), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Featured Image from URL (FIFU)
13 fiches
Featured Image from URL (FIFU) <= 5.3.1 – Authenticated (Contributor+) Server-Side Request Forgery via 'fifu_input_url'
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.3.1. This is due to insufficient validation of user-supplied URLs before passing them to the getimagesize()…
*-5.3.1
5.3.2
09/01/2026
Featured Image from URL (FIFU) <= 5.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featured Image custom fields in all versions up to, and including, 5.2.7 due to insufficient input sanitization and output escaping.…
*-5.2.7
5.2.8
06/10/2025
Featured Image from URL (FIFU) <= 5.2.7 – Missing Authorization to Password Protected Post Disclosure
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() function in all versions up to, and including, 5.2.7. This makes it possible…
*-5.2.7
5.2.8
25/09/2025
Featured Image from URL (FIFU) <= 5.2.7 – Authenticated (Admin+) SQL Injection
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function in all versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of…
*-5.2.7
5.2.8
25/09/2025
Featured Image from URL (FIFU) <= 5.2.7 – Unauthenticated Information Exposure via Log File
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…
*-5.2.7
5.2.8
25/09/2025
Featured Image from URL (FIFU) <= 5.2.7 – Authenticated (Admin+) SQL Injection
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_featured_image() function in all versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of…
*-5.2.7
5.2.8
25/09/2025
Featured Image from URL <= 4.8.2 – Missing Authorization
The Featured Image from URL plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the fifu_get_private_data_permissions_check() function in versions up to, and including, 4.8.2. This makes it possible for authenticated…
*-4.8.2
4.8.3
05/07/2024
Featured Image from URL <= 4.8.1 – Missing Authorization
The Featured Image from URL plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fifu_save_sizes_api() function in versions up to, and including, 4.8.1. This makes it possible for unauthenticated…
*-4.8.1
4.8.2
28/06/2024
Featured Image from URL (FIFU) <= 4.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via fifu_input_url
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes it…
*-4.6.2
4.6.3
19/02/2024
Featured Image from URL (FIFU) <= 4.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This…
*-4.5.3
4.5.4
14/12/2023
Featured Image from URL (FIFU) <= 4.0.0 – Stored Cross-Site Scripting
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘input’ parameter in versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.0.0
4.0.1
05/07/2022
Featured Image from URL (FIFU) <= 3.9.9 – Cross-Site Request Forgery
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.9. This is due to missing or incorrect nonce validation on the fifu_update_menu_options function. This makes it…
*-3.9.9
4.0.0
30/06/2022
Featured Image from URL <= 2.7.7 – Missing Authorization on REST API routes
The Feature Image from URL plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on REST routes in versions up to, and including, 2.7.7. This makes it possible for unauthenticated attackers to access the…
*-2.7.7
2.7.8
24/12/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.