PT-2026-22410 · WordPress · Featured Image From Content Wordpress Plugin

4Lec4St

·

Published

2026-02-27

·

Updated

2026-02-28

·

CVE-2026-27759

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Featured Image from Content WordPress plugin versions prior to 1.7
Description The Featured Image from Content WordPress plugin has a server-side request forgery issue. Users with Author-level access can retrieve internal HTTP resources. This is due to insecure URL fetching and file write operations, which allow attackers to obtain sensitive internal data and save it to publicly accessible upload directories.
Recommendations Update to Featured Image from Content WordPress plugin version 1.7 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27759

Affected Products

Featured Image From Content Wordpress Plugin