Impact
The vulnerability is an unauthenticated broken access control in versions of the bPlugins YT Player plugin for WordPress up to 2.0.9. It allows an unauthenticated user to access functionality that is intended only for logged‑in administrators or authorized roles. Based on the description, it is inferred that the attacker may be able to modify plugin settings or perform privileged actions, thereby compromising the integrity of the site. This assessment does not presume any specific exploitation outcome beyond the stated loss of access control.
Affected Systems
WordPress sites that use the bPlugins YT Player plugin version 2.0.9 or earlier.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % suggests a low probability of active exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The flaw is unauthenticated, so an attacker can target the public web interface of the plugin, likely without additional prerequisites.
OpenCVE Enrichment