The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view settings for playlists.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 22 Nov 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view settings for playlists. | |
Title | Ultimate YouTube Video & Shorts Player With Vimeo <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Setting Exposure | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-11-22T11:34:08.980Z
Reserved: 2024-11-18T18:09:55.316Z
Link: CVE-2024-11355

Updated: 2024-11-22T11:29:03.443Z

Status : Received
Published: 2024-11-22T06:15:19.450
Modified: 2024-11-22T06:15:19.450
Link: CVE-2024-11355

No data.