PT-2023-16292 · WordPress · Auto Featured Image

Dc11

·

Published

2023-03-13

·

Updated

2023-03-16

·

CVE-2023-0477

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Auto Featured Image (Auto Post Thumbnail) WordPress plugin versions prior to 3.9.16
Description The issue is caused by incorrect file extension validation, allowing any user with at least Author privileges to upload arbitrary files, such as PHP files, through an AJAX endpoint.
Recommendations For versions prior to 3.9.16, update to version 3.9.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX endpoint or disabling file uploads for users with Author privileges until a patch is applied.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-0477

Affected Products

Auto Featured Image