WordPress security by component
Auto Featured Image (Auto Post Thumbnail)
Plugin description
Auto Featured Image (Auto Post Thumbnail) automatically generates featured images for WordPress posts from available content or media.
Auto Featured Image (Auto Post Thumbnail) (auto-featured-image) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 27, 2024; the highest published CVSS base score is 8.8.
Plugin slug:
auto-featured-imageLatest vulnerability
CVE-2024-6054: Auto Featured Image: Dangerous file upload
Auto Featured Image is affected by dangerous file upload. Exploitation requires an authenticated contributor account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
| Safe version |
|
||
|---|---|---|---|
| Jun 27, 2024 |
CVE-2024-6054
Auto Featured Image: Dangerous file upload
Auto Featured Image is affected by dangerous file upload. Exploitation requires an authenticated contributor account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Mar 13, 2023 |
CVE-2023-0477
Auto Featured Image (Auto Post Thumbnail): A security weakness
Auto Featured Image (Auto Post Thumbnail) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Dec 13, 2021 |
CVE-2021-24932
Auto Featured Image (Auto Post Thumbnail): Cross-site scripting
Auto Featured Image (Auto Post Thumbnail) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|