CVE-2026-101147: Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Featured Image from URL (FIFU) Freeto a version that resolves this vulnerability.Fixed in 6.0.8 - Upgrade
Upgrade
Featured Image from URL (FIFU) Premiumto a version that resolves this vulnerability.Fixed in 8.2.8
Event History
Frequently Asked Questions
Which installations are affected?
Affected versions are FIFU Free before 6.0.8 and FIFU Premium before 8.2.8.
What does an attacker need to exploit this issue?
The attacker needs to induce a logged-in WordPress administrator to make a request using a crafted URL. The flaw allows the REST API nonce check to be disabled for that request.
What could an attacker do through a successful attack?
A successful CSRF attack can cause the administrator to perform REST API actions. Creating a new administrator account is an example given in the vulnerability data.
What should be done if the plugin is in use?
Update FIFU Free to 6.0.8 or later, or FIFU Premium to 8.2.8 or later. Until updating, reduce exposure by ensuring administrator accounts do not follow untrusted crafted URLs while logged in.