Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control levels within the Feeds for YouTube WordPress plugin. This weakness, mapped to CWE-862, means an attacker could potentially gain unauthorized access to protected content or perform actions beyond their intended permissions, compromising confidentiality or integrity of the site’s data.
Affected Systems
Syed Balkhi’s Feeds for YouTube plugin for WordPress, affecting all releases up to and including version 2.4.0. Users running any of those versions are susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Inferred attack vectors likely involve any user able to invoke the plugin’s functionalities, possibly requiring authentication to view protected YouTube feeds. The lack of explicit authentication checks would allow malicious actors to bypass intended access restrictions.
OpenCVE Enrichment