Impact
The vulnerability is a missing authorization flaw in the pupunzi mb.YTPlayer plugin that allows users to bypass correctly configured access control levels. An attacker could exploit this to perform actions within the plugin that should be restricted, potentially accessing, modifying, or deleting media resources and associated metadata. The weakness is classified as CWE‑862, which indicates improper enforcement of authorization rules leading to unauthorized privilege escalation.
Affected Systems
Vendors and products affected include pupunzi mb.YTPlayer, a WordPress plugin. The product version impacted spans all releases from the initial release up through version 3.3.8. No later versions are known to be vulnerable.
Risk and Exploitability
The CVSS score of 5.4 places the vulnerability in the medium range. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. It is not listed in CISA’s KEV catalog, indicating no known active exploitation. The likely attack vector is through the web interface of a WordPress site where the plugin is installed; an attacker only needs to reach plugin-specific endpoints that bypass authorization checks. Exploitation requires no special user privileges, meaning any user who can access the site may attempt to exploit the flaw.
OpenCVE Enrichment
EUVD