CVE-2026-61970: WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability
Published Jul 13, 2026
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.
Affected Software
2 affected components
Themeisle Auto Featured Image (Auto Post Thumbnail)<=5.0.4
WordPress Auto Featured Image (Auto Post Thumbnail)<=5.0.4
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61970?
CVE-2026-61970 has a medium severity rating of 4.9.
2
How does CVE-2026-61970 impact WordPress sites?
CVE-2026-61970 allows for Server-Side Request Forgery (SSRF), potentially exposing sensitive data.
3
How can I fix CVE-2026-61970?
To fix CVE-2026-61970, update the Themeisle Auto Featured Image plugin to version 5.0.5 or higher.
4
Which versions of the Auto Featured Image plugin are affected by CVE-2026-61970?
CVE-2026-61970 affects Auto Featured Image plugin versions from n/a through 5.0.4.
5
What type of vulnerability is CVE-2026-61970 classified as?
CVE-2026-61970 is classified as a Server-Side Request Forgery (SSRF) vulnerability.