CVE-2025-13393
The Featured Image from URL plugin for WordPress contains a security flaw that allows attackers with Contributor-level access or higher to bypass normal web request restrictions, enabling them to query and modify internal system information via the fifu_input_url parameter in the Elementor widget integration. This vulnerability arises from inadequate validation of user-submitted URLs before passing them to the getimagesize() function. Affected versions include all releases up to and including 5.3.1.
Based on public CVE data (MITRE/NVD).