Sceawere

Vulnerability Detail

CVE-2026-96671UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CSRF in Featured Image Plugin

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
fifu.app
Product
Featured Image from URL
Attack Type
Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Cross-Site Request Forgery (CSRF) vulnerability in fifu.app Featured Image from URL featured-image-from-url allows Cross Site Request Forgery.This issue affects Featured Image from URL: from n/a through 6.0.7.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-09T10:16:45.697Z",
  "pubdate": "2026-10-09T10:16:45.697Z",
  "executiveSummary": "The Featured Image from URL (fifu.app) plugin is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability affecting versions up to 6.0.7.\nThis security flaw allows an unauthenticated remote attacker to trick an authenticated administrator into executing unintended, malicious actions on the WordPress installation.\nThe vulnerability occurs due to the lack of proper anti-CSRF nonce validation or request verification on critical administrative functions within the plugin.\nAn attacker can exploit this by enticing a logged-in administrator to interact with a crafted malicious URL or website.\nSuccessful exploitation may result in unauthorized configuration changes, potential data manipulation, or other actions permitted under the administrator's security context.\nThe risk is categorized as significant because administrative accounts typically possess broad privileges, and the exploit does not require the attacker to possess credentials, relying instead on the active session of the victim.",
  "technicalDetails": "The vulnerability is a classic Cross-Site Request Forgery (CSRF), resulting from the application's failure to enforce sufficient state-changing request validation.\nIn the context of the Featured Image from URL plugin, the administrative endpoints responsible for updating plugin settings or triggering image processing functionality do not implement cryptographically secure anti-CSRF tokens (nonces) or referer/origin header checks.\nWhen a plugin perform administrative operations via HTTP GET or POST requests, it must ensure that the request was initiated by an authorized user intentionally. Without a nonce, the browser automatically includes ambient credentials, such as session cookies, with any request sent to the domain.\nExploitation flow: 1. An attacker constructs a malicious payload, such as a hidden HTML form or a scripted request targeting the specific plugin functionality that alters system state. 2. The attacker delivers this payload to an authenticated administrator via a phishing link, an infected third-party site, or an injected advertisement. 3. When the administrator visits the attacker-controlled page, the browser automatically submits the malicious request to the vulnerable WordPress installation.\nBecause the victim is authenticated as an administrator, the server processes the request as a legitimate command from the site owner, allowing the attacker to bypass access control.\nThe vulnerability remains active in all versions of Featured Image from URL from n/a through 6.0.7. The scope of impact is limited by the specific endpoints exposed by the plugin that lack CSRF protection; however, if these endpoints control global plugin configuration, the impact can include complete redirection of image sources or persistent changes to the application's functionality.\nPost-exploitation, the attacker could manipulate plugin settings to point images to malicious external domains, facilitating potential client-side attacks against end-users who visit the site, or perform other administrative tasks permitted by the plugin's interface."
}
CVE-2026-96671: CSRF in Featured Image Plugin (HIGH Severity, CVSS: 8.8) | Sceawere