CVE-2025-13794: Auto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkactiongeneratehandler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete or generate featured images on posts they do not own.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13794?
CVE-2025-13794 is considered a medium severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2025-13794?
To fix CVE-2025-13794, you should update the Auto Featured Image plugin to version 4.2.2 or later.
Who is affected by CVE-2025-13794?
CVE-2025-13794 affects all versions of the Auto Featured Image plugin for WordPress up to and including 4.2.1.
What kind of attack does CVE-2025-13794 allow?
CVE-2025-13794 allows authenticated attackers to modify data without appropriate capability checks.
Is CVE-2025-13794 a zero-day vulnerability?
No, CVE-2025-13794 is not a zero-day vulnerability as it has been publicly disclosed and a patch is available.