Extension WordPress

Vulnérabilités Featured Image from URL (FIFU)

Cette page rassemble les failles publiées pour Featured Image from URL (FIFU), leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
0Critiques
13Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Featured Image from URL (FIFU)

13 fiches

CVE-2025-13393 Moyenne · 4,3
Featured Image from URL (FIFU)

Featured Image from URL (FIFU) <= 5.3.1 – Authenticated (Contributor+) Server-Side Request Forgery via 'fifu_input_url'

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.3.1. This is due to insufficient validation of user-supplied URLs before passing them to the getimagesize()…

Versions affectées

*-5.3.1

Correctif

5.3.2

Publication

09/01/2026

CVE-2025-7400 Moyenne · 6,4
Featured Image from URL (FIFU)

Featured Image from URL (FIFU) <= 5.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featured Image custom fields in all versions up to, and including, 5.2.7 due to insufficient input sanitization and output escaping.…

Versions affectées

*-5.2.7

Correctif

5.2.8

Publication

06/10/2025

CVE-2025-9984 Moyenne · 5,3
Featured Image from URL (FIFU)

Featured Image from URL (FIFU) <= 5.2.7 – Missing Authorization to Password Protected Post Disclosure

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() function in all versions up to, and including, 5.2.7. This makes it possible…

Versions affectées

*-5.2.7

Correctif

5.2.8

Publication

25/09/2025

CVE-2025-9985 Moyenne · 5,3
Featured Image from URL (FIFU)

Featured Image from URL (FIFU) <= 5.2.7 – Unauthenticated Information Exposure via Log File

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…

Versions affectées

*-5.2.7

Correctif

5.2.8

Publication

25/09/2025

CVE-2025-10037 Moyenne · 4,9
Featured Image from URL (FIFU)

Featured Image from URL (FIFU) <= 5.2.7 – Authenticated (Admin+) SQL Injection

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_featured_image() function in all versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-5.2.7

Correctif

5.2.8

Publication

25/09/2025

CVE-2024-1496 Moyenne · 6,4
Featured Image from URL (FIFU)

Featured Image from URL (FIFU) <= 4.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via fifu_input_url

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-4.6.2

Correctif

4.6.3

Publication

19/02/2024

CVE-2023-6561 Moyenne · 6,4
Featured Image from URL (FIFU)

Featured Image from URL (FIFU) <= 4.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-4.5.3

Correctif

4.5.4

Publication

14/12/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités