CVE-2026-101147

CVE-2026-101147 published: The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which c...

View full NVD advisory → ← Back to CVE watch