WordPress security by component
Auto Featured Image (Auto Post Thumbnail)
Plugin description
Auto Featured Image (Auto Post Thumbnail) automatically generates featured images for WordPress posts from available post content or media.
Auto Featured Image (Auto Post Thumbnail) (auto-post-thumbnail) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest published CVSS base score is 6.4.
Plugin slug:
auto-post-thumbnailLatest vulnerability
CVE-2026-61970: Auto Featured Image (Auto Post Thumbnail): Server-side request forgery
Auto Featured Image (Auto Post Thumbnail) is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 5.0.4.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-61970
Auto Featured Image (Auto Post Thumbnail): Server-side request forgery
Auto Featured Image (Auto Post Thumbnail) is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 5.0.4.
|
5.0.5 |
CVE4.9
NVDPending
|
| Dec 16, 2025 |
CVE-2025-13794
Auto Featured Image (Auto Post Thumbnail): A security weakness
Auto Featured Image (Auto Post Thumbnail) is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 01, 2024 |
CVE-2024-38719
Auto Featured Image (Auto Post Thumbnail): A security weakness
Auto Featured Image (Auto Post Thumbnail) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 31, 2024 |
CVE-2023-7073
Auto Featured Image (Auto Post Thumbnail): Server-side request forgery
Auto Featured Image (Auto Post Thumbnail) is affected by server-side request forgery. Exploitation requires an authenticated author account. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 29, 2024 |
CVE-2024-33629
Auto Featured Image (Auto Post Thumbnail): Server-side request forgery
Auto Featured Image (Auto Post Thumbnail) is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.4
NVDPending
|