PT-2026-1702 · WordPress · Wordpress+1

Dmitry Ignatyev

·

Published

2026-01-10

·

Updated

2026-01-10

·

CVE-2025-13393

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Featured Image from URL (FIFU) plugin for WordPress versions up to and including 5.3.1
Description The software contains a Server-Side Request Forgery issue due to inadequate validation of user-supplied URLs before they are passed to the getimagesize() function within the Elementor widget integration. This allows authenticated attackers with Contributor-level access or higher to make web requests to arbitrary locations originating from the web application. Exploitation occurs through the fifu input url parameter in the FIFU Elementor widget.
Recommendations Versions prior to and including 5.3.1 should be updated.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-13393

Affected Products

Featured Image From Url
Wordpress