CVE-2026-27759
Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticated server-side request forgery vulnerability that allows Author-level users to fetch internal HTTP resources. Attackers can exploit insecure URL fetching and file write operations to retrieve sensitive internal data and store it in web-accessible upload directories.
Published:Feb 27, 2026
Last Modified:Apr 16, 2026
EPS:Feb 27, 2026
EPSS Score:0.0005
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Dhrumil Kumbhani
Product
Featured Image From Content
Dhrumil Kumbhani
Featured Image From Content
Vendor
Wordpress
Product
Wordpress
Wordpress
Wordpress
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
