| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17244 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Featured Image from URL (FIFU) <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via fifu_input_url |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 04 Mar 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fifu
Fifu featured Image From Url |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:fifu:featured_image_from_url:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Fifu
Fifu featured Image From Url |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:02:49.905Z
Reserved: 2024-02-14T16:31:07.013Z
Link: CVE-2024-1496
Updated: 2024-08-01T18:40:21.187Z
Status : Modified
Published: 2024-02-29T01:43:52.083
Modified: 2026-04-08T18:20:41.243
Link: CVE-2024-1496
No data.
OpenCVE Enrichment
No data.
EUVD