CVE · Medium

CVE-2022-2241 — Featured Image from URL (FIFU) [featured-image-from-url] < 4.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2241 Featured Image from URL (FIFU) [featured-image-from-url] < 4.0.0 Improper Encoding or Escaping of Output Medium 6.1 < 4.0.0 4.0.0 2022-06-30

CVE-2022-2241

The Featured Image from URL plugin for WordPress before version 4.0.0 contains a cross-site request forgery vulnerability because the fifu_update_menu_options function lacks proper nonce verification. An unauthenticated attacker could exploit this flaw by crafting a malicious request that, if clicked by a site administrator, would modify plugin settings without authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.