Cross-Site Request Forgery in Featured Image from URL Plugin for WordPress
CVE-2026-101147
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
Badges
What is CVE-2026-101147?
The Featured Image from URL (FIFU) plugin for WordPress is susceptible to Cross-Site Request Forgery due to improper enforcement of the REST API nonce in versions prior to 6.0.8 and 8.2.8 for the Premium variant. This security flaw enables attackers to exploit the vulnerability through crafted URLs, empowering them to trick a logged-in administrator into executing unintended REST API actions, including the potential creation of new administrator accounts. Users are urged to upgrade to the latest versions to mitigate this risk effectively.
Affected Version(s)
Featured Image from URL (FIFU) 6.0.0 < 6.0.8
Featured Image from URL (FIFU) Premium 6.8.0 < 8.2.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.