PT-2025-51372 · WordPress · Auto Featured Image

Dmitry Ignatyev

·

Published

2025-12-16

·

Updated

2025-12-17

·

CVE-2025-13794

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Auto Featured Image (Auto Post Thumbnail) plugin for WordPress versions through 4.2.1
Description The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress has a flaw that allows unauthorized modification of data. A missing capability check within the bulk action generate handler function permits authenticated attackers with Contributor-level access or higher to delete or generate featured images on posts they are not authorized to manage.
Recommendations Update the Auto Featured Image (Auto Post Thumbnail) plugin to a version later than 4.2.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13794

Affected Products

Auto Featured Image