PT-2026-22410 · WordPress · Featured Image From Content Wordpress Plugin
4Lec4St
·
Published
2026-02-27
·
Updated
2026-02-28
·
CVE-2026-27759
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Featured Image from Content WordPress plugin versions prior to 1.7
Description
The Featured Image from Content WordPress plugin has a server-side request forgery issue. Users with Author-level access can retrieve internal HTTP resources. This is due to insecure URL fetching and file write operations, which allow attackers to obtain sensitive internal data and save it to publicly accessible upload directories.
Recommendations
Update to Featured Image from Content WordPress plugin version 1.7 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Featured Image From Content Wordpress Plugin