Conversation
supportWordfence is reporting a security vulnerability with this plugin. When will it be patched?
For the sake of completeness, here you can read a bit more about the issue: https://www.cve.org/CVERecord?id=CVE-2024-33629 https://patchstack.com/database/vulnerability/auto-post-thumbnail/wordpress-auto-featured-image-auto-post-thumbnail-plugin-4-0-0-server-side-request-forgery-ssrf-vulnerability and, of course, from Wordfence themselves: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/auto-post-thumbnail-2/auto-featured-image-auto-post-thumbnail-400-authenticated-author-server-side-request-forgery It’s unlikely that this vulnerability can be successfully exploited — it’s therefore relatively low-risk. Nevertheless, there is a vulnerability, which most definitely should be patched & fixed ASAP.
We are trying to find out more about this vulnerability, it may already be closed. In any case, it does not pose a threat to your site. We will try to release the update as soon as possible!
Hi Alexander, is there an estimated time of delivery for the patch? While it is partially reassuring that the vulnerability is low risk, as someone else said there still is a vulnerabilty and it might be exploited. Thanks for your support!
For the sake of completeness, here you can read a bit more about the issue: https://www.cve.org/CVERecord?id=CVE-2024-33629 https://patchstack.com/database/vulnerability/auto-post-thumbnail/wordpress-auto-featured-image-auto-post-thumbnail-plugin-4-0-0-server-side-request-forgery-ssrf-vulnerability and, of course, from Wordfence themselves: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/auto-post-thumbnail-2/auto-featured-image-auto-post-thumbnail-400-authenticated-author-server-side-request-forgery It’s unlikely that this vulnerability can be successfully exploited — it’s therefore relatively low-risk. Nevertheless, there is a vulnerability, which most definitely should be patched & fixed ASAP.
We are trying to find out more about this vulnerability, it may already be closed. In any case, it does not pose a threat to your site. We will try to release the update as soon as possible!
Hi Alexander, is there an estimated time of delivery for the patch? While it is partially reassuring that the vulnerability is low risk, as someone else said there still is a vulnerabilty and it might be exploited. Thanks for your support!