CVE-2025-9985

Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.


We have discovered 1,931 live websites that are affected by CVE-2025-9985.

Run a Free Instant Scan




Affected Software

Product  Featured Image From Url
Category Wordpress Plugins
Vulnerable Domains1,931 live websites (63% of Featured Image From Url install base)
Vulnerable Versions
  • from 0 through 5.2.7
Vulnerable Versions Count185 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-532 Insertion of Sensitive Information into Log File



Details

  • Published - Sep 26, 2025
  • Updated - Sep 26, 2025

Credits

  • ifoundbug (finder)

Website Distribution by Country

Number of websites using CVE-2025-9985
United States731 websites



Germany148 websites
Russia75 websites
GB73 websites
Iran71 websites
France70 websites
Vietnam58 websites
Sweden47 websites
Japan43 websites
Cyprus41 websites

Website Distribution by TLD

Number of websites using CVE-2025-9985
.com929 websites
.org101 websites
.net84 websites
.ru63 websites
.de43 websites
.se34 websites
.dk25 websites
.nl24 websites
.co.uk24 websites
.it23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-9985

Top websites that are affected by CVE-2025-9985. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com Singapore**,***
***.***.il Israel**,***
*****.io United States***,***
**********.com China***,***
**************.vn Vietnam***,***
*********.com United States***,***
****.*************.com United States***,***
**********.com Germany***,***
**********.com United States***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2025-9985 is Insertion of Sensitive Information into Log File in Featured Image From Url
A total of 1,931 websites have been identified as vulnerable to CVE-2025-9985, based on global website indexing conducted by WebTechSurvey.
The Featured Image From Url is affected by the CVE-2025-9985 vulnerability.
Featured Image From Url versions up to and including 5.2.7 are vulnerable to CVE-2025-9985.