Impact
Missing authorization checks in the Video List Manager plugin allow an attacker to access or manipulate functionality that should be gated by access control lists. This could lead to unauthorized viewing, editing, or deletion of video entries, compromising the confidentiality and integrity of the data stored by the plugin. The weakness is a classic example of broken access control (CWE-862).
Affected Systems
WordPress installations that have thanhtungtnt Video List Manager plugin versions up to and including 1.7 are affected. Administrators and potentially other authenticated users could exploit the flaw if the plugin does not enforce proper role checks.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a low probability of widespread exploitation. Since this vulnerability is not listed in the CISA KEV catalog, it is not currently known to be actively exploited. The likely attack vector is via standard web requests to the plugin’s endpoints, where the missing ACL checks allow unauthenticated or insufficiently privileged users to perform restricted actions.
OpenCVE Enrichment
EUVD