SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-61970

MEDIUM · CVSS 4.9 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A Server-Side Request Forgery (SSRF) vulnerability exists in the Themeisle Auto Featured Image plugin, affecting versions up to and including 5.0.4. This flaw allows attackers to send unauthorized requests from the server, potentially leading to data exposure or further exploitation of internal services. Organizations using this plugin should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-61970
Severity
MEDIUM
CVSS
4.9
EPSS
0.12%

Original NVD Description

Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.