Impact
The PixelPlay video‑autoplay plugin for WordPress is missing an authorization check when handling the 'clear_api_type' API parameter, allowing any requester to delete API keys that the site administrator has configured for services such as Pixabay, Unsplash, Pixels, and OpenAI, thereby crippling the plugin’s core functionality and any site features that rely on image or AI content; this weakness is classified as CWE‑862: Missing Authorization.
Affected Systems
All installations of the PixelPlay plugin for WordPress running version 1.0.2 or earlier, developed by kamleshyadav, are affected; the vulnerability exists within the plugin’s API endpoint that processes the 'clear_api_type' request and applies to any WordPress site with the plugin activated.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and although the EPSS score is not available, the lack of authentication and the simplicity of the HTTP request make exploitation highly likely in practice; the vulnerability is not yet listed in the CISA KEV catalog, yet it poses a significant risk by allowing attackers to disrupt site operations through deletion of essential API keys, which must be regenerated before normal functionality can resume.
OpenCVE Enrichment