Cross-Site Request Forgery in Featured Image from URL Plugin for WordPress
CVE-2026-101147

Currently unrated

Key Information:

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-101147?

The Featured Image from URL (FIFU) plugin for WordPress is susceptible to Cross-Site Request Forgery due to improper enforcement of the REST API nonce in versions prior to 6.0.8 and 8.2.8 for the Premium variant. This security flaw enables attackers to exploit the vulnerability through crafted URLs, empowering them to trick a logged-in administrator into executing unintended REST API actions, including the potential creation of new administrator accounts. Users are urged to upgrade to the latest versions to mitigate this risk effectively.

Affected Version(s)

Featured Image from URL (FIFU) 6.0.0 < 6.0.8

Featured Image from URL (FIFU) Premium 6.8.0 < 8.2.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Enrico Marcolini
Claudio Marchesini
Dottor Marc
WPScan
.