CVE · Medium

CVE-2024-1496 — Featured Image from URL (FIFU) [featured-image-from-url] < 4.6.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1496 Featured Image from URL (FIFU) [featured-image-from-url] < 4.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.6.3 4.6.3 2024-02-19

CVE-2024-1496

The Featured Image from URL plugin below version 4.6.3 contains a cross-site scripting vulnerability that could permit an attacker to inject malicious scripts into a website, including redirects, ads, or arbitrary HTML content that executes when visitors access the site. This flaw was discovered by Nikolas and remains unfixed as of the advisory date. Users of affected versions face potential compromise of their website's integrity through script injection attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.