Cross-Site Request Forgery Vulnerability in Featured Image from URL by fifu.app
CVE-2026-96671

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-96671?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Featured Image from URL plugin by fifu.app. This security issue allows unauthorized commands to be transmitted from a user that the web application trusts. It affects the plugin versions from n/a through 6.0.7, which can lead to significant security risks if exploited. Users of this plugin should ensure they are aware of this vulnerability and take necessary precautions, including updating to the latest version to mitigate potential threats.

Affected Version(s)

Featured Image from URL 0 <= 6.0.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ChuongVN | Patchstack Bug Bounty Program
.