CVE-2025-31820
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-31820 is a Missing Authorization vulnerability affecting the Automatic Featured Images from Videos plugin, versions n/a through 1.2.4, by webdevstudios. This issue arises due to incorrectly configured access control security levels, enabling attackers to exploit the vulnerability and gain unauthorized access. Successful exploitation could potentially lead to serious consequences, including unintended plugin functionality or unauthorized access to sensitive data. Users are encouraged to update to the latest version of the plugin or contact their security teams to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.