The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update featured image of any post.
History

Wed, 04 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Krasenslavov
Krasenslavov featured Image Plus
Weaknesses CWE-862
CPEs cpe:2.3:a:krasenslavov:featured_image_plus:*:*:*:*:*:wordpress:*:*
Vendors & Products Krasenslavov
Krasenslavov featured Image Plus

Fri, 30 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 May 2025 07:30:00 +0000

Type Values Removed Values Added
Description The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update featured image of any post.
Title Featured Image Plus <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Featured Image Update
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-05-30T07:23:40.575Z

Updated: 2025-05-30T13:56:18.607Z

Reserved: 2025-05-08T12:38:03.594Z

Link: CVE-2025-4431

cve-icon Vulnrichment

Updated: 2025-05-30T13:56:12.522Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-30T08:15:19.383

Modified: 2025-06-04T18:30:52.393

Link: CVE-2025-4431

cve-icon Redhat

No data.