Impact
The Featured Image from URL (FIFU) WordPress plugin, both free and premium editions before versions 6.0.8 and 8.2.8 respectively, fails to correctly enforce the REST API nonce, effectively disabling the check for the entire request when a crafted URL is used. This flaw allows an attacker to force a logged‑in administrator to perform arbitrary REST API actions, such as creating a new administrator account, thereby granting the attacker full control over the site. The weakness is a classic CSRF whose exploitation requires a crafted link; the likely attack vector is a CSRF attack where an attacker lures a logged‑in administrator to a malicious URL that triggers the REST API call.
Affected Systems
The vulnerability affects the Featured Image from URL (FIFU) WordPress plugin for the free edition before version 6.0.8 and the premium edition before version 8.2.8. No other WordPress plugins or core components are impacted. The third‑party plugin vendor is unknown, but the product is identified by its name.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and while the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, the flaw remains a genuine risk to sites with the affected plugins. The vulnerability is exploitable via CSRF by directing a logged‑in administrator to visit a malicious URL, enabling the attacker to create a new administrator account and gain full administrative privileges. Proper mitigation should be prioritized due to the high impact on confidentiality, integrity, and availability.
OpenCVE Enrichment