All 3 CVE vulnerabilities found in Quick Featured Images, with AI-generated Chinese analysis, references, and POCs.
Vendor: kybernetikservices
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-11980 | Quick Featured Images <= 13.7.3 - Authenticated (Editor+) SQL Injection via delete_orphaned CWE-89 | 4.9 | Medium | 2025-11-08 |
| CVE-2025-11176 | Quick Featured Images <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation CWE-639 | 4.3 | Medium | 2025-10-15 |
| CVE-2024-3664 | Quick Featured Images <= 13.7.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Thumbnail Deletion/Setting CWE-862 | 4.3 | Medium | 2024-04-23 |
All 3 known CVE vulnerabilities affecting Quick Featured Images with full Chinese analysis, references, and POCs where available.