PLUGIN SECURITY

Is Featured Image From Url safe?

Use remote media as the featured image and beyond.

What this plugin does

  • Slug: featured-image-from-url
  • Author: fifu.app
  • 60000+ active installs
  • 92/100 rating (264 reviews on wordpress.org)
  • 7344284 all-time downloads
  • On WordPress.org since 2015-10-03

featuredimageremoteurlwoocommerce

Maintenance status

  • Latest known version: 6.0.0
  • Last updated: 2026-08-20 1:47pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 8.1+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

13 known CVEs on file for Featured Image From Url.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-73340 Featured Image from URL (FIFU) [featured-image-from-url] < 6.0.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 6.0.0 6.0.0 2026-08-12 ✓ fixed in latest
CVE-2025-13393 Featured Image from URL (FIFU) [featured-image-from-url] < 5.3.2 Server-Side Request Forgery (SSRF) Medium 4.3 < 5.3.2 5.3.2 2026-01-09 ✓ fixed in latest
CVE-2025-10037 Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 5.2.8 5.2.8 2025-09-25 ✓ fixed in latest
CVE-2025-10036 Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 5.2.8 5.2.8 2025-09-25 ✓ fixed in latest
CVE-2024-37516 Featured Image from URL (FIFU) [featured-image-from-url] < 4.8.3 Missing Authorization Medium 6.3 < 4.8.3 4.8.3 2024-07-05 ✓ fixed in latest
CVE-2024-37276 Featured Image from URL (FIFU) [featured-image-from-url] < 4.8.2 Missing Authorization Medium 5.3 < 4.8.2 4.8.2 2024-06-28 ✓ fixed in latest
CVE-2024-1496 Featured Image from URL (FIFU) [featured-image-from-url] < 4.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.6.3 4.6.3 2024-02-19 ✓ fixed in latest
CVE-2023-6561 Featured Image from URL (FIFU) [featured-image-from-url] < 4.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.5.4 4.5.4 2023-12-14 ✓ fixed in latest
+ 12 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2278 Featured Image from URL (FIFU) [featured-image-from-url] < 4.0.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.0.1 4.0.1 2022-07-05 ✓ fixed in latest
CVE-2022-2241 Featured Image from URL (FIFU) [featured-image-from-url] < 4.0.0 Improper Encoding or Escaping of Output Medium 6.1 < 4.0.0 4.0.0 2022-06-30 ✓ fixed in latest
Featured Image from URL (FIFU) [featured-image-from-url] < 2.7.8 Unknown < 2.7.8 2.7.8 2019-12-27 ✓ fixed in latest
Featured Image from URL (FIFU) [featured-image-from-url] < 2.7.8 Unknown < 2.7.8 2.7.8 2019-12-24 ✓ fixed in latest
Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.2.8 5.2.8 0000-00-00 ✓ fixed in latest
Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 Insertion of Sensitive Information into Log File Medium 5.3 < 5.2.8 5.2.8 0000-00-00 ✓ fixed in latest
Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 Missing Authorization Medium 5.3 < 5.2.8 5.2.8 0000-00-00 ✓ fixed in latest
Featured Image from URL (FIFU) [featured-image-from-url] < 2.7.8 Unknown < 2.7.8 2.7.8 ✓ fixed in latest
Featured Image from URL <= 2.7.7 - Missing Access Controls on REST routes Unknown < 2.7.8 2.7.8 ✓ fixed in latest
CVE-2025-9984 Featured Image from URL (FIFU) < 5.2.8 - Missing Authorization to Password Protected Post Disclosure Unknown < 5.2.8 5.2.8 ✓ fixed in latest
CVE-2025-9985 Featured Image from URL (FIFU) < 5.2.8 - Unauthenticated Information Exposure via Log File Unknown < 5.2.8 5.2.8 ✓ fixed in latest
CVE-2025-7400 Featured Image from URL (FIFU) < 5.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields Unknown < 5.2.8 5.2.8 ✓ fixed in latest

How to fix it

Keep Featured Image From Url updated — 6.0.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.