Auto Featured Image
cpe:2.3:a:cm-wp:auto_featured_image:*:*:*:*:wordpress:*:*
A vulnerability exists in the Auto Featured Image (Auto Post Thumbnail) plugin for WordPress, in all versions through 4.2.1. The issue arises from a lack of proper capability checks in the bulk_action_generate_handler function, allowing authenticated attackers with Contributor-level access or higher to manipulate featured images on posts they do not own. This includes the unauthorized deletion or generation of featured images.
Exploitation of this vulnerability allows for unauthorized modification of post thumbnail data, enabling attackers to delete or add featured images on posts they do not own.
To reproduce this vulnerability, an authenticated user with Contributor-level access can use the bulk action feature to delete or generate featured images on posts they do not own. This can be done by selecting the appropriate bulk action option and applying it to the targeted posts.
Users are advised to update the Auto Featured Image (Auto Post Thumbnail) plugin to version 4.2.2 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.