CVE-2024-37516
- EPSS 0.12%
- Veröffentlicht 01.11.2024 15:15:29
- Zuletzt bearbeitet 01.11.2024 20:24:53
Missing Authorization vulnerability in fifu.App Featured Image from URL allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image from URL: from n/a through 4.8.2.
CVE-2024-37276
- EPSS 0.16%
- Veröffentlicht 01.11.2024 15:15:23
- Zuletzt bearbeitet 01.11.2024 20:24:53
Missing Authorization vulnerability in fifu.App Featured Image from URL allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image from URL: from n/a through 4.8.1.
CVE-2024-1496
- EPSS 0.22%
- Veröffentlicht 29.02.2024 01:43:52
- Zuletzt bearbeitet 04.03.2025 12:25:17
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes i...
CVE-2023-6561
- EPSS 0.24%
- Veröffentlicht 11.01.2024 09:15:49
- Zuletzt bearbeitet 21.11.2024 08:44:06
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it...
CVE-2022-2278
- EPSS 0.24%
- Veröffentlicht 01.08.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:00:40
The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html...
CVE-2022-2241
- EPSS 0.3%
- Veröffentlicht 01.08.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:36
The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of valida...