Automatic Featured Images from Videos
Automatic Featured Images from Videos has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 2 of the records (100%).
Every one of the 2 issues recorded for Automatic Featured Images from Videos has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Automatic Featured Images from Videos is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-24535Automatic Featured Images from Videos <= 1.2.7 - Missing Authorization
Read the full analysisVulnerability Records

Automatic Featured Images from Videos
Author
webdevstudios
When placing a YouTube or Vimeo video within the first 4000 characters of a post, the thumbnail of that video will automatically be uploaded and set as the featured image for the post as long as the post does not already have a set featured image. In addition, after setting the video thumbnail as the featured image, an “is_video” post meta field is updated to allow for the use of conditional statements within your loop. Pluginize was launched in 2016 by WebDevStudios to promote, support, and house all of their WordPress products. Pluginize is not only creating new products for WordPress all the time, but also provides ongoing support and development for WordPress community favorites like CPTUI, CMB2, and more.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C