WPIntell

Source evidence

Security Vulnerability

Auto Featured Image (Auto Post Thumbnail) · support · 2024-05-03T14:05:00+00:00

complaintsentiment
highseverity
1.0relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 26 rows with source links

15.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

22 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
mikepalmer unresolved
Wordfence is reporting a security vulnerability with this plugin. When will it be patched? For the sake of completeness, here you can read a bit more about the issue: https://www.cve.org/CVERecord?id=CVE-2024-33629 https://patchstack.com/database/vulnerability/auto-post-thumbnail/wordpress-auto-featured-image-auto-post-thumbnail-plugin-4-0-0-server-side-request-forgery-ssrf-vulnerability and, of course, from Wordfence themselves: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/auto-post-thumbnail-2/auto-featured-image-auto-post-thumbnail-400-authenticated-author-server-side-request-forgery It’s unlikely that this vulnerability can be successfully exploited — it’s therefore relatively low-risk. Nevertheless, there is a vulnerability, which most definitely should be patched & fixed ASAP. We are trying to find out more about this vulnerability, it may already be closed. In any case, it does not pose a threat to your site. We will try to release the update as soon as possible! Hi Alexander, is there an estimated time of delivery for the patch? While it is partially reassuring that the vulnerability is low risk, as someone else said there still is a vulnerabilty and it might be exploited. Thanks for your support!

Comments

3 shown
Gwyneth Llewelyn 2024-05-05T03:12:00+00:00

For the sake of completeness, here you can read a bit more about the issue: https://www.cve.org/CVERecord?id=CVE-2024-33629 https://patchstack.com/database/vulnerability/auto-post-thumbnail/wordpress-auto-featured-image-auto-post-thumbnail-plugin-4-0-0-server-side-request-forgery-ssrf-vulnerability and, of course, from Wordfence themselves: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/auto-post-thumbnail-2/auto-featured-image-auto-post-thumbnail-400-authenticated-author-server-side-request-forgery It’s unlikely that this vulnerability can be successfully exploited — it’s therefore relatively low-risk. Nevertheless, there is a vulnerability, which most definitely should be patched & fixed ASAP.

Alexander Kovalev 2024-05-06T06:26:00+00:00

We are trying to find out more about this vulnerability, it may already be closed. In any case, it does not pose a threat to your site. We will try to release the update as soon as possible!

xeinar 2024-05-15T16:35:00+00:00

Hi Alexander, is there an estimated time of delivery for the patch? While it is partially reassuring that the vulnerability is low risk, as someone else said there still is a vulnerabilty and it might be exploited. Thanks for your support!