Impact
This CVE describes a Cross‑Site Request Forgery flaw in the fifu.app WordPress Featured Image from URL plugin that allows an attacker to trick an authenticated user into performing image‑upload actions without authorization. The vulnerability exists because the plugin does not properly validate the user’s intent for image updates, resulting in unauthorized changes to featured images. The flaw is identified as CWE‑352, indicating a lack of anti‑CSRF protection.
Affected Systems
The issue affects the WordPress Featured Image from URL plugin, version 6.0.7 and earlier, for all installations using that plugin via fifu.app. Any WordPress site that has not upgraded past 6.0.7 is potentially exposed.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity with high exploitability; because this is a CSRF vulnerability, a threat actor can trigger it from a remote site by embedding a malicious form or image that submits a request to the vulnerable plugin endpoint. Although the EPSS score is unavailable, the lack of a KEV listing does not negate the risk—many WordPress sites still run the affected plugin. Immediate patching is recommended to eliminate this high‑impact vulnerability.
OpenCVE Enrichment