Auto Featured Image (Auto Post Thumbnail), CVE-2021-24932
- CVE, Research URL
- Application
- Published on
- Dec 13, 2021
- Research Description
- The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.
- Affected versions
-
max 3.9.16.
- Status
-
vulnerable