plugin

Auto Post Thumbnail Vulnerabilities

16 known security issues reported for the Auto Post Thumbnail WordPress plugin. Most recent disclosed Jul 31, 2026.

1 high 6 medium

Running Auto Post Thumbnail on your site? Check whether your installed version is affected.

Scan your site free

Auto Featured Image (Auto Post Thumbnail) <= 5.0.4 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web appli...

CVSS:
6.4
Affected:
up to 5.0.4
Fixed in:
5.0.5
Disclosed:
Jul 31, 2026

CVE-2026-61970 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 4.2.2

unknown

[en] The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-leve...

Affected:
up to 4.2.2
Fixed in:
4.2.2
Disclosed:
Dec 16, 2025

CVE-2025-13794 on NVD →

Auto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification

medium

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level acc...

CVSS:
4.3
Affected:
up to 4.2.1
Fixed in:
4.2.2
Disclosed:
Dec 15, 2025

CVE-2025-13794 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 4.2.0

unknown

[en] The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via the upload_to_library function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary l...

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Oct 28, 2025

CVE-2025-10145 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 4.1.3

unknown

[en] Missing Authorization vulnerability in Creative Motion Auto Featured Image (Auto Post Thumbnail) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through 4.1.2.

Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Nov 1, 2024

CVE-2024-38719 on NVD →

Auto Featured Image (Auto Post Thumbnail) <= 4.1.2 - Missing Authorization

medium

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized acti...

CVSS:
4.3
Affected:
up to 4.1.2
Fixed in:
4.1.3
Disclosed:
Jul 11, 2024

CVE-2024-38719 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] <= 4.0.0 (unfixed)

unknown

[en] The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.0 via the upload_to_library AJAX action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrar...

Affected:
up to 4.0.0
Fix:
No patched version reported
Disclosed:
May 31, 2024

CVE-2023-7073 on NVD →

Auto Featured Image (Auto Post Thumbnail) <= 4.1.7 - Authenticated (Author+) Server-Side Request Forgery

medium

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via the upload_to_library AJAX action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary loc...

CVSS:
6.4
Affected:
up to 4.1.7
Fixed in:
4.2.0
Disclosed:
May 30, 2024

CVE-2023-7073 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 4.1.4

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Creative Motion Auto Featured Image (Auto Post Thumbnail).This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through 4.0.0.

Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Apr 29, 2024

CVE-2024-33629 on NVD →

Auto Featured Image (Auto Post Thumbnail) <= 4.1.3 - Authenticated (Author+) Server-Side Request Forgery

medium

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary locations originating from the web applic...

CVSS:
6.4
Affected:
up to 4.1.3
Fixed in:
4.1.4
Disclosed:
Apr 25, 2024

CVE-2024-33629 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 3.9.16

unknown

[en] The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

Affected:
up to 3.9.16
Fixed in:
3.9.16
Disclosed:
Mar 13, 2023

CVE-2023-0477 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 3.9.16

unknown

Update the WordPress Auto Featured Image (Auto Post Thumbnail) plugin to the latest available version (at least 3.9.16). Wordfence discovered and reported this Arbitrary File Download vulnerability in WordPress Auto Featured Image (Auto Post Thumbnail) Plugin. This could allow a malicious actor to download any file fro...

Affected:
up to 3.9.16
Fixed in:
3.9.16
Disclosed:
Feb 8, 2023

Auto Featured Image (Auto Post Thumbnail) <= 3.9.15 - Authenticated (Author+) Arbitrary File Upload

high

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.9.15. This allows authenticated users with author-level permissions to upload arbitrary files from remote sources onto the affected site'...

CVSS:
7.2
Affected:
up to 3.9.15
Fixed in:
3.9.16
Disclosed:
Feb 7, 2023

CVE-2023-0477 on NVD →

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 3.9.16

unknown

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.9.15. This allows authenticated users with author-level permissions to upload arbitrary files from remote sources onto the affected site'...

Affected:
up to 3.9.16
Fixed in:
3.9.16
Disclosed:
Feb 7, 2023

Auto Featured Image (Auto Post Thumbnail) [auto-post-thumbnail] < 3.9.3

unknown

[en] The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.

Affected:
up to 3.9.3
Fixed in:
3.9.3
Disclosed:
Dec 13, 2021

CVE-2021-24932 on NVD →

Auto Featured Image <= 3.9.2 - Reflected Cross-Site Scripting

medium

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.

CVSS:
6.1
Affected:
up to 3.9.2
Fixed in:
3.9.3
Disclosed:
Nov 15, 2021

CVE-2021-24932 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database