Vulnerabilities (CVE)

Filtered by vendor Cm-wp Subscribe
Filtered by product Auto Featured Image
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24932 1 Cm-wp 1 Auto Featured Image 2021-12-15 4.3 MEDIUM 6.1 MEDIUM
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.