Executive brief
Featured Image Generator is a WordPress plugin that helps create and manage featured images for blog posts and pages. The plugin contains a broken access control vulnerability that allows unauthenticated users to access pages or perform actions they should not be permitted to, potentially exposing private content or enabling unauthorized modifications.
Technical details
The vulnerability is a broken access control issue (OWASP A1) in Featured Image Generator versions up to 1.3.4, affecting the plugin's permission validation mechanisms. The flaw allows unauthenticated attackers to bypass access restrictions and access or manipulate functionality they should not have permission to use. No specific authentication or network preconditions are required for exploitation. An attacker can access restricted pages or perform privileged actions such as viewing other users' data or modifying plugin settings. As of the advisory date, no official patch was available.
Affected products
- Aum Watcharapon Featured Image Generator <= 1.3.4
Timeline
- 2025-10-16: disclosed: Reported by Legion Hunter
- 2025-12-31: advisory: Published by Patchstack