Vulnerabilities > Krasenslavov > Featured Image Plus > 1.6.4

DATE CVE VULNERABILITY TITLE RISK
2025-05-30 CVE-2025-4431 Improper Access Control vulnerability in Krasenslavov Featured Image Plus
The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.3.
network
low complexity
krasenslavov CWE-284
4.3