Impact
This vulnerability is a Server Side Request Forgery flaw in the WordPress plugin Auto Featured Image (Auto Post Thumbnail). It permits a web attacker to have the WordPress server send HTTP requests to any URL that the attacker can supply. The weakness is identified as CWE-918. While the official description does not detail the exact consequences, the attack could allow access to internal network resources or exfiltration of data from the host, thus compromising confidentiality of services that the server can reach. Integrity and availability impacts are not described in the source material.
Affected Systems
The affected system is the Themeisle Auto Featured Image (Auto Post Thumbnail) plugin for WordPress; all releases through version 5.0.4 are vulnerable.
Risk and Exploitability
The CVSS score of 4.9 categorises the vulnerability as medium severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The plugin behaves the same way for any user with standard front‑end access, so no special privileges are required. The likely attack vector involves supplying a crafted URL parameter to the plugin’s image URL handling pathway, causing the server to forward the request. Because of the broader lack of urgency indicated by the EPSS score, the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment