Unauthorized Data Modification in Auto Featured Image Plugin for WordPress
CVE-2025-13794
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 December 2025
What is CVE-2025-13794?
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress suffers from a security flaw that permits unauthorized data modification. Due to a missing capability check in the bulk_action_generate_handler function, authenticated attackers with Contributor-level access can manipulate featured images on posts they do not own. This vulnerability affects all versions of the plugin up to and including 4.2.1, exposing the system to the risk of unwanted changes to post images, which could potentially lead to further exploitation. For detailed analysis, visit the reference links provided.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Auto Featured Image (Auto Post Thumbnail) * <= 4.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved