Impact
The Automatic Featured Images from Videos plugin for WordPress exposes a missing authorization flaw, identified as CWE-862, that permits unauthenticated users to invoke administrative endpoints intended for privileged users. This broken access control could allow the attacker to alter site content, change settings, or retrieve data that should be restricted, thereby compromising the integrity and confidentiality of the WordPress installation.
Affected Systems
Any WordPress site running the webdevstudios Automatic Featured Images from Videos plugin version 1.2.7 or older is vulnerable. The flaw affects the entire plugin codebase, not a specific component, so all users of the plugin on a WordPress site are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. With an EPSS score below 1%, the probability of exploitation is very low, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector involves sending crafted HTTP requests to the plugin’s administrative endpoints without authentication, which an attacker can do from any network location with access to the site’s URL.
OpenCVE Enrichment