Post Featured Video
Post Featured Video has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Post Featured Video has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. Post Featured Video is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-60137Post Featured Video <= 1.7 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Post Featured Video
Author
Galaxy Weblinks
Post Featured Video is a very nifty responsive video plugin that helps your users to see a YouTube or Vimeo video or Custom HTML MP4 video instead of the featured image on the blog and blog detail page. Add the URL of YouTube or Vimeo in the specific field or upload video in the backend of the post/page and your user will have the pleasure to watch video in place of featured image. Post Featured video plugin is highly customizable. You can display video in lightbox, enable autoplay video, enable display mode ie. youtube, Vimeo or upload MP4 video. It can replace the post featured image with a video. Features This plugin provides the following features: * Option for enables/disable video for post types. * Autoplay Video * Enable/disable popup/lightbox for video * Display mode for video (YouTube, Vimeo, Custom MP4 Video upload) and much more. * Option to set the height of YouTube video. * Option to display videos only on single posts, pages, and custom post types. Here’s a link to the documentation for the plugin. This will help you learn more about its features and how to use it. Documentation For any feedback or queries regarding this plugin, please contact our Support team.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C