Featured Image From Url
Vendor:
First CVE: Aug 1, 2022 · Active for 3 years
4
Total CVEs
More Total CVEs than 75% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Featured Image From Url over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2022
3 years ago
Most Recent CVE
Feb 29, 2024
880 days ago
CVE Severity & Scoring
Featured Image From Url4 CVEs
100%
All CVEs353,173 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required4 (100.0%)
Privileges Required
Low2 (50.0%)
High1 (25.0%)
None1 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2278MEDIUM The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its settings, which could allow high privilege users such as admin t | Aug 1, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-1496MEDIUM The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 du | Feb 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-6561MEDIUM The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up to, and including, 4.5.3 due | Jan 11, 2024 | 5.4 | 17 | NO | NO |
CVE-2022-2241MEDIUM The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin | Aug 1, 2022 | 6.1 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Featured Image From Url
Top CWEs
Versions
No cataloged versions.