← All CVEs

CVE-2025-9985

medium · 5.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

5.3
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2025-09-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-532

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-9985