Fifu maintains a focused plugin or extension product, Featured Image from URL, where its vulnerability profile centers on web-application output-handling weaknesses—specifically cross-site scripting and improper output encoding. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fifu over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2278MEDIUM The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its settings, which could allow high privilege users such as admin t | Aug 1, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-1496MEDIUM The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 du | Feb 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-6561MEDIUM The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up to, and including, 4.5.3 due | Jan 11, 2024 | 5.4 | 17 | NO | NO |
CVE-2022-2241MEDIUM The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin | Aug 1, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fifu.
Media articles that mention a CVE ID that affects a product developed by Fifu — matched by CVE ID, not by vendor name.