CVE · Medium

CVE-2024-37516 — Featured Image from URL (FIFU) [featured-image-from-url] < 4.8.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37516 Featured Image from URL (FIFU) [featured-image-from-url] < 4.8.3 Missing Authorization Medium 6.3 < 4.8.3 4.8.3 2024-07-05

CVE-2024-37516

The Featured Image from URL plugin contains a capability verification weakness in the fifu_get_private_data_permissions_check() function that impacts versions 4.8.2 and earlier. Attackers with authenticated contributor-level permissions or higher can abuse multiple REST API endpoints to modify data without proper authorization checks. The vulnerability was fixed in version 4.8.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.