Unauthorized Data Modification in Auto Featured Image Plugin for WordPress
CVE-2025-13794
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 December 2025
What is CVE-2025-13794?
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress suffers from a security flaw that permits unauthorized data modification. Due to a missing capability check in the bulk_action_generate_handler function, authenticated attackers with Contributor-level access can manipulate featured images on posts they do not own. This vulnerability affects all versions of the plugin up to and including 4.2.1, exposing the system to the risk of unwanted changes to post images, which could potentially lead to further exploitation. For detailed analysis, visit the reference links provided.
Affected Version(s)
Auto Featured Image (Auto Post Thumbnail) * <= 4.2.1