Extension WordPress
Vulnérabilités Auto Featured Image (Auto Post Thumbnail)
Cette page rassemble les failles publiées pour Auto Featured Image (Auto Post Thumbnail), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Auto Featured Image (Auto Post Thumbnail)
6 fiches
Auto Featured Image <= 4.2.1 – Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it…
*-4.2.1
4.2.2
15/12/2025
Auto Featured Image (Auto Post Thumbnail) <= 4.1.2 – Missing Authorization
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.2. This makes it possible for authenticated…
*-4.1.2
4.1.3
11/07/2024
Auto Featured Image (Auto Post Thumbnail) <= 4.1.7 – Authenticated (Author+) Server-Side Request Forgery
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via the upload_to_library AJAX action. This makes it possible for authenticated attackers, with author-level…
*-4.1.7
4.2.0
30/05/2024
Auto Featured Image (Auto Post Thumbnail) <= 4.1.3 – Authenticated (Author+) Server-Side Request Forgery
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with author-level access and above, to make…
*-4.1.3
4.1.4
25/04/2024
Auto Featured Image (Auto Post Thumbnail) <= 3.9.15 – Authenticated (Author+) Arbitrary File Upload
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.9.15. This allows authenticated users with author-level permissions to upload…
*-3.9.15
3.9.16
07/02/2023
Auto Featured Image <= 3.9.2 – Reflected Cross-Site Scripting
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.
*-3.9.2
3.9.3
15/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.