PT-2026-22410 · WordPress · Featured Image From Content Wordpress Plugin
4Lec4St
·
Publicado
2026-02-27
·
Atualizado
2026-02-28
·
CVE-2026-27759
CVSS v4.0
5.3
Média
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Featured Image from Content WordPress plugin versions prior to 1.7
Description
The Featured Image from Content WordPress plugin has a server-side request forgery issue. Users with Author-level access can retrieve internal HTTP resources. This is due to insecure URL fetching and file write operations, which allow attackers to obtain sensitive internal data and save it to publicly accessible upload directories.
Recommendations
Update to Featured Image from Content WordPress plugin version 1.7 or later.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Featured Image From Content Wordpress Plugin