Input validation vulnerability in Featured Image Plus – Quick & Bulk Edit with Unsplash 1.6.4

The Featured Image Plus plugin for WordPress has a security issue called Server-Side Request Forgery. This can be found in all versions up to 1.6.4 and is caused by the fip_get_image_options() function. If an attacker with administrator access or higher uses this vulnerability, they can make requests to any location on the internet through the plugin. This can be used to access and change information from internal services.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.