Description
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.
Published: 2026-04-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch Now
AI Analysis

Impact

The vulnerability is a missing authorization check in the embedplus Youtube Embed Plus plugin for WordPress. An attacker can exploit incorrectly configured access control security levels to reach administrative interfaces that normally require higher privileges. This flaw allows unauthorized manipulation of the plugin’s settings and the embedded content, potentially leading to the insertion of malicious videos or alteration of user‑generated content. The weakness is classified as CWE-862.

Affected Systems

WordPress sites that have the embedplus Youtube Embed Plus plugin from its earliest version up through any release dated 14.2.4 or earlier are affected. The plugin is identified by embedplus and is commonly used on sites that embed video content.

Risk and Exploitability

The CVSS score and EPSS data are not publicly disclosed, and the vulnerability is not listed in the CISA KEV catalog, so the exact quantitative risk cannot be determined. However, because the flaw permits unauthorized access to privileged plugin functions via the web interface, the risk is considered high for sites where the plugin’s administrative pages are reachable. The likely attack vector is through crafted HTTP requests sent to the plugin’s backend endpoints, and exploitation does not appear to require additional pre‑conditions beyond the presence of the vulnerable plugin installation.

Generated by OpenCVE AI on April 8, 2026 at 10:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Youtube Embed Plus plugin to a version newer than 14.2.4
  • Verify that only administrators have access to the plugin’s settings and editor pages
  • Review and harden role‑based permissions on your WordPress site
  • Monitor logs for unauthorized access attempts

Generated by OpenCVE AI on April 8, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Embedplus
Embedplus youtube Embed Plus
Wordpress
Wordpress wordpress
Vendors & Products Embedplus
Embedplus youtube Embed Plus
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.
Title WordPress Youtube Embed Plus plugin <= 14.2.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Embedplus Youtube Embed Plus
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-08T08:30:11.011Z

Reserved: 2026-04-07T10:47:37.759Z

Link: CVE-2026-39485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:23.253

Modified: 2026-04-08T21:26:35.910

Link: CVE-2026-39485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:43:13Z

Weaknesses