Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure

2025-09-25 16:00
ifoundbug

Strategic Overview

Status
Patched in 5.2.8
Affected Version<= 5.2.7
CVSS5.3Medium
CVECVE-2025-9984
View all Featured Image from URL (FIFU) vulnerabilities

Vulnerability Overview

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() function in all versions up to, and including, 5.2.7. This makes it possible for unauthenticated attackers to read private/password protected posts.

Technical Analysis

REMEDIATION: Update to version 5.2.8, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C