Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31213 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() function in all versions up to, and including, 5.2.7. This makes it possible for unauthenticated attackers to read private/password protected posts. |
Fri, 26 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Sep 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fifu
Fifu featured Image From Url Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fifu
Fifu featured Image From Url Wordpress Wordpress wordpress |
Fri, 26 Sep 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() function in all versions up to, and including, 5.2.7. This makes it possible for unauthenticated attackers to read private/password protected posts. | |
| Title | Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:09:48.955Z
Reserved: 2025-09-04T13:32:38.868Z
Link: CVE-2025-9984
Updated: 2025-09-26T19:36:20.888Z
Status : Deferred
Published: 2025-09-26T05:15:36.733
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-9984
No data.
OpenCVE Enrichment
Updated: 2026-04-21T03:00:06Z
EUVD