WordPress Core versions up to and including 6.2 have a security vulnerability that allows unauthenticated users to update the thumbnail image associated with existing attachments. This is accomplished by tricking an authenticated user with the right permissions into clicking a link. Although this vulnerability is present, its impact is very minimal.