PLUGIN SECURITY
Is Featured Image From Url safe?
Use remote media as the featured image and beyond.
What this plugin does
- Slug:
featured-image-from-url - Author: fifu.app
- 60000+ active installs
- 92/100 rating (264 reviews on wordpress.org)
- 7344284 all-time downloads
- On WordPress.org since 2015-10-03
featuredimageremoteurlwoocommerce
Maintenance status
- Latest known version: 6.0.0
- Last updated: 2026-08-20 1:47pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 8.1+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
13 known CVEs on file for Featured Image From Url.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-73340 | Featured Image from URL (FIFU) [featured-image-from-url] < 6.0.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.0.0 | 6.0.0 | 2026-08-12 | ✓ fixed in latest |
| CVE-2025-13393 | Featured Image from URL (FIFU) [featured-image-from-url] < 5.3.2 | Server-Side Request Forgery (SSRF) | Medium 4.3 | < 5.3.2 | 5.3.2 | 2026-01-09 | ✓ fixed in latest |
| CVE-2025-10037 | Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 5.2.8 | 5.2.8 | 2025-09-25 | ✓ fixed in latest |
| CVE-2025-10036 | Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 5.2.8 | 5.2.8 | 2025-09-25 | ✓ fixed in latest |
| CVE-2024-37516 | Featured Image from URL (FIFU) [featured-image-from-url] < 4.8.3 | Missing Authorization | Medium 6.3 | < 4.8.3 | 4.8.3 | 2024-07-05 | ✓ fixed in latest |
| CVE-2024-37276 | Featured Image from URL (FIFU) [featured-image-from-url] < 4.8.2 | Missing Authorization | Medium 5.3 | < 4.8.2 | 4.8.2 | 2024-06-28 | ✓ fixed in latest |
| CVE-2024-1496 | Featured Image from URL (FIFU) [featured-image-from-url] < 4.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.6.3 | 4.6.3 | 2024-02-19 | ✓ fixed in latest |
| CVE-2023-6561 | Featured Image from URL (FIFU) [featured-image-from-url] < 4.5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.5.4 | 4.5.4 | 2023-12-14 | ✓ fixed in latest |
+ 12 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2022-2278 | Featured Image from URL (FIFU) [featured-image-from-url] < 4.0.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.0.1 | 4.0.1 | 2022-07-05 | ✓ fixed in latest |
| CVE-2022-2241 | Featured Image from URL (FIFU) [featured-image-from-url] < 4.0.0 | Improper Encoding or Escaping of Output | Medium 6.1 | < 4.0.0 | 4.0.0 | 2022-06-30 | ✓ fixed in latest |
| — | Featured Image from URL (FIFU) [featured-image-from-url] < 2.7.8 | — | Unknown | < 2.7.8 | 2.7.8 | 2019-12-27 | ✓ fixed in latest |
| — | Featured Image from URL (FIFU) [featured-image-from-url] < 2.7.8 | — | Unknown | < 2.7.8 | 2.7.8 | 2019-12-24 | ✓ fixed in latest |
| — | Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.2.8 | 5.2.8 | 0000-00-00 | ✓ fixed in latest |
| — | Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 | Insertion of Sensitive Information into Log File | Medium 5.3 | < 5.2.8 | 5.2.8 | 0000-00-00 | ✓ fixed in latest |
| — | Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8 | Missing Authorization | Medium 5.3 | < 5.2.8 | 5.2.8 | 0000-00-00 | ✓ fixed in latest |
| — | Featured Image from URL (FIFU) [featured-image-from-url] < 2.7.8 | — | Unknown | < 2.7.8 | 2.7.8 | — | ✓ fixed in latest |
| — | Featured Image from URL <= 2.7.7 - Missing Access Controls on REST routes | — | Unknown | < 2.7.8 | 2.7.8 | — | ✓ fixed in latest |
| CVE-2025-9984 | Featured Image from URL (FIFU) < 5.2.8 - Missing Authorization to Password Protected Post Disclosure | — | Unknown | < 5.2.8 | 5.2.8 | — | ✓ fixed in latest |
| CVE-2025-9985 | Featured Image from URL (FIFU) < 5.2.8 - Unauthenticated Information Exposure via Log File | — | Unknown | < 5.2.8 | 5.2.8 | — | ✓ fixed in latest |
| CVE-2025-7400 | Featured Image from URL (FIFU) < 5.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields | — | Unknown | < 5.2.8 | 5.2.8 | — | ✓ fixed in latest |
How to fix it
Keep Featured Image From Url updated — 6.0.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Imsanity — 200000+ active installs — 98/100 (292) — max PHP 8.4
- Firelight Lightbox — 200000+ active installs — 96/100 (355) — max PHP 8.4
- Responsive Lightbox & Gallery — 100000+ active installs — 98/100 (1999) — max PHP 8.4
- Simple Lightbox — 100000+ active installs — 86/100 (239) — max PHP <8.0
- reSmush.it : The original free image compressor and optimizer plugin — 100000+ active installs — 86/100 (165)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.