CVE-2025-13393
Featured Image from URL (FIFU)
Minimum safe version
5.3.2
Update to 5.3.2 or later to address 15 fixable vulnerabilities
Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure
Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
CVE-2025-10036
Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields
CVE-2025-10037
CVE-2024-37516
CVE-2024-37276
CVE-2024-1496
WordPress Featured Image from URL Plugin <= 4.5.3 is vulnerable to Cross Site Scripting (XSS)
Featured Image from URL <= 2.7.7 - Missing Access Controls on REST routes
Featured Image from URL <= 2.7.7 - Missing Authorization on REST API routes
CVE-2022-2241
CVE-2022-2278
WordPress Featured Image from URL plugin <= 2.7.7 - Missing Access Controls on REST routes vulnerability