Description
Cross-Site Request Forgery (CSRF) vulnerability in fifu.app Featured Image from URL featured-image-from-url allows Cross Site Request Forgery.This issue affects Featured Image from URL: from n/a through 6.0.7.
Published: 2026-10-09
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Cross-Site Request Forgery
Action: Patch
AI Analysis

Impact

This CVE describes a Cross‑Site Request Forgery flaw in the fifu.app WordPress Featured Image from URL plugin that allows an attacker to trick an authenticated user into performing image‑upload actions without authorization. The vulnerability exists because the plugin does not properly validate the user’s intent for image updates, resulting in unauthorized changes to featured images. The flaw is identified as CWE‑352, indicating a lack of anti‑CSRF protection.

Affected Systems

The issue affects the WordPress Featured Image from URL plugin, version 6.0.7 and earlier, for all installations using that plugin via fifu.app. Any WordPress site that has not upgraded past 6.0.7 is potentially exposed.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity with high exploitability; because this is a CSRF vulnerability, a threat actor can trigger it from a remote site by embedding a malicious form or image that submits a request to the vulnerable plugin endpoint. Although the EPSS score is unavailable, the lack of a KEV listing does not negate the risk—many WordPress sites still run the affected plugin. Immediate patching is recommended to eliminate this high‑impact vulnerability.

Generated by OpenCVE AI on October 9, 2026 at 12:00 UTC.

Remediation

Vendor Solution

Update the WordPress Featured Image from URL plugin to the latest available version (at least 6.0.8).


OpenCVE Recommended Actions

  • Update the WordPress Featured Image from URL plugin to at least version 6.0.8.
  • Disable or remove the plugin if an update is delayed until a patch is available.
  • Configure a web application firewall or security plugin to block unauthenticated POST requests to the plugin’s image update endpoint.

Generated by OpenCVE AI on October 9, 2026 at 12:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in fifu.app Featured Image from URL featured-image-from-url allows Cross Site Request Forgery.This issue affects Featured Image from URL: from n/a through 6.0.7.
Title WordPress Featured Image from URL plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:21.368Z

Reserved: 2026-09-23T15:08:53.373Z

Link: CVE-2026-96671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T10:16:45.697

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-96671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:15:05Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)