CVE-2026-101147
Received Received - Intake

Featured Image from URL Plugin REST API CSRF Vulnerability

Vulnerability report for CVE-2026-101147, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: WPScan

Description

The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF attack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpbeaverbuilder featured_image_from_url to 6.0.8 (exc)
wpbeaverbuilder featured_image_from_url_premium to 8.2.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) flaw in the Featured Image from URL (FIFU) WordPress plugins. The plugins fail to properly enforce REST API nonce checks, allowing attackers to bypass security by crafting a URL that disables nonce verification for the entire request. This could trick an authenticated administrator into performing unintended actions.

Detection Guidance

Check if you are using vulnerable versions of the FIFU plugins (free before 6.0.8 or premium before 8.2.8). Inspect WordPress admin logs for unexpected administrator account creations or REST API actions. Review server access logs for suspicious URLs or requests targeting the REST API.

Impact Analysis

An attacker could exploit this to make a logged-in administrator perform actions like creating a new administrator account. This could lead to full site compromise, unauthorized access, or further attacks on the WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Unauthorized account creation or data access could result in legal penalties or reputational damage.

Mitigation Strategies

Update the FIFU plugins to version 6.0.8 (free) or 8.2.8 (premium) immediately. Disable the REST API if not required or restrict access via firewall rules. Monitor for unauthorized administrator accounts and review user permissions regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101147. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart