Description
Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.
Published: 2026-07-13
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Server Side Request Forgery flaw in the WordPress plugin Auto Featured Image (Auto Post Thumbnail). It permits a web attacker to have the WordPress server send HTTP requests to any URL that the attacker can supply. The weakness is identified as CWE-918. While the official description does not detail the exact consequences, the attack could allow access to internal network resources or exfiltration of data from the host, thus compromising confidentiality of services that the server can reach. Integrity and availability impacts are not described in the source material.

Affected Systems

The affected system is the Themeisle Auto Featured Image (Auto Post Thumbnail) plugin for WordPress; all releases through version 5.0.4 are vulnerable.

Risk and Exploitability

The CVSS score of 4.9 categorises the vulnerability as medium severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The plugin behaves the same way for any user with standard front‑end access, so no special privileges are required. The likely attack vector involves supplying a crafted URL parameter to the plugin’s image URL handling pathway, causing the server to forward the request. Because of the broader lack of urgency indicated by the EPSS score, the issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 1, 2026 at 10:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Auto Featured Image (Auto Post Thumbnail) to a release newer than 5.0.4 that removes the SSRF flaw.
  • If an upgrade cannot be performed immediately, temporarily disable or delete the plugin from the WordPress installation to eliminate the attack surface.
  • Configure network or application firewall rules to restrict outbound HTTP/HTTPS traffic from WordPress to only trusted domains, thereby limiting the potential impact of any SSRF exploitation.

Generated by OpenCVE AI on August 1, 2026 at 10:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Themeisle
Themeisle auto Featured Image (auto Post Thumbnail)
Wordpress
Wordpress wordpress
Vendors & Products Themeisle
Themeisle auto Featured Image (auto Post Thumbnail)
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.
Title WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Themeisle Auto Featured Image (auto Post Thumbnail)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T10:08:07.875Z

Reserved: 2026-07-13T06:13:50.885Z

Link: CVE-2026-61970

cve-icon Vulnrichment

Updated: 2026-07-13T10:08:00.872Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)