Executive brief
Themeisle Auto Featured Image, a WordPress plugin used to automatically generate thumbnails for posts, contains a security flaw that could allow an attacker to make unauthorized requests from the web server. By exploiting this vulnerability, a logged-in user with low-level permissions could potentially scan internal network resources or access sensitive data that is not intended to be public. This could lead to a breach of internal systems or unauthorized information disclosure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Themeisle Auto Featured Image (Auto Post Thumbnail) plugin (auto-post-thumbnail) for WordPress. The flaw is present in versions up to and including 5.0.4 and is classified under CWE-918. An attacker with low-level authenticated access (Subscriber or higher) can exploit this vulnerability to make the server perform unauthorized web requests. This can be used to bypass firewalls, interact with internal services, or perform port scanning on the local network. The vulnerability is addressed in version 5.0.5.
Affected products
- Themeisle Auto Featured Image (Auto Post Thumbnail) <= 5.0.4
Timeline
- 2026-07-13: advisory
- 2026-07-13: patched: Fixed in version 5.0.5