CVE-2025-9985: Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9985?
CVE-2025-9985 has been classified as a medium severity vulnerability due to sensitive information exposure.
How do I fix CVE-2025-9985?
To fix CVE-2025-9985, update the Featured Image from URL (FIFU) plugin to version 5.2.8 or later.
Who is affected by CVE-2025-9985?
CVE-2025-9985 affects all versions of the Featured Image from URL (FIFU) plugin for WordPress up to and including version 5.2.7.
What type of vulnerability is CVE-2025-9985?
CVE-2025-9985 is a sensitive information exposure vulnerability due to publicly accessible log files.
Can unauthenticated users exploit CVE-2025-9985?
Yes, unauthenticated attackers can exploit CVE-2025-9985 to access sensitive information contained in the log files.