Automatic Featured Images from Videos

Automatic Featured Images from Videos has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 2 of the records (100%).

Every one of the 2 issues recorded for Automatic Featured Images from Videos has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Automatic Featured Images from Videos is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Automatic Featured Images from Videos vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2026-24535

Automatic Featured Images from Videos <= 1.2.7 - Missing Authorization

Read the full analysis

Vulnerability Records

2 records
Automatic Featured Images from Videos banner
Latestv1.2.9

Automatic Featured Images from Videos

webdevstudios

Author

webdevstudios

4.6(36)
92/100
Last Updated
2026-07-14 (2mo ago)
Active Installs
7,000+
Downloads
144,997
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2014-07-16 (12y ago)

When placing a YouTube or Vimeo video within the first 4000 characters of a post, the thumbnail of that video will automatically be uploaded and set as the featured image for the post as long as the post does not already have a set featured image. In addition, after setting the video thumbnail as the featured image, an “is_video” post meta field is updated to allow for the use of conditional statements within your loop. Pluginize was launched in 2016 by WebDevStudios to promote, support, and house all of their WordPress products. Pluginize is not only creating new products for WordPress all the time, but also provides ongoing support and development for WordPress community favorites like CPTUI, CMB2, and more.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C