Description
Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload auto-post-after-image-upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Post After Image Upload: from n/a through <= 1.6.
Published: 2025-03-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Auto Post After Image Upload plugin has a missing authorization check that enables an attacker to exploit improperly configured access control levels. Because the plugin fails to verify user permissions before allowing image uploads to trigger automated post creation, a malicious user could cause arbitrary content to be published on the site. This results in compromised content integrity and potential defacement, aligning with CWE‑862 – Broken Access Control.

Affected Systems

All users of the Shaharia Azam Auto Post After Image Upload plugin with versions from the earliest release and including all releases up to and including 1.6 are affected. No later version is mentioned as patched, so any installation using 1.6 or earlier is at risk.

Risk and Exploitability

The CVSS base score is 4.3, placing the vulnerability in the moderate range. The EPSS score is less than 1 %, indicating a low probability of active exploitation at the time of this analysis. The vulnerability is not included in the CISA KEV list. Likely attack vector involves a user with some level of site access who can upload images; the lack of proper authorization checks permits the automatic generation of posts without verification of privileges, suggesting that exploitation would require the attacker to be able to initiate the image upload process, likely through the plugin’s public interface or a compromised account. The exact exploitation method is not explicitly detailed in the advisory, so this assessment is inferred from the described broken access control.

Generated by OpenCVE AI on May 1, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Auto Post After Image Upload plugin to the latest release available from the vendor; if a newer version is not available, discontinue using the plugin entirely.
  • Disable or remove the auto‑post feature if it is not required, and ensure that the WordPress site’s role‑based access controls restrict the ability to upload images and create posts to trusted administrators only.
  • Conduct a security review of user permissions on the WordPress site to enforce least‑privilege policies and monitor for unauthorized content creation.

Generated by OpenCVE AI on May 1, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8790 Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Post After Image Upload: from n/a through 1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Post After Image Upload: from n/a through 1.6. Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload auto-post-after-image-upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Post After Image Upload: from n/a through <= 1.6.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 31 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Post After Image Upload: from n/a through 1.6.
Title WordPress Auto Post After Image Upload plugin <= 1.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:10.306Z

Reserved: 2025-03-31T10:06:10.341Z

Link: CVE-2025-31611

cve-icon Vulnrichment

Updated: 2025-03-31T13:39:43.651Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T13:15:55.283

Modified: 2026-04-23T15:28:04.367

Link: CVE-2025-31611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T03:00:08Z

Weaknesses