The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to change or remove featured images of other user's posts.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 15 Oct 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to change or remove featured images of other user's posts. | |
Title | Quick Featured Images <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation | |
Weaknesses | CWE-639 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-15T05:23:48.130Z
Reserved: 2025-09-29T19:57:18.202Z
Link: CVE-2025-11176

No data.

Status : Received
Published: 2025-10-15T06:15:38.163
Modified: 2025-10-15T06:15:38.163
Link: CVE-2025-11176

No data.

No data.