Filtered by vendor Creative Motion Subscriptions
Filtered by product Auto Featured Image Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-7073 1 Creative Motion 1 Auto Featured Image 2024-11-21 6.4 Medium
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.0 via the upload_to_library AJAX action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.