Executive brief
The bPlugins Tiktok Feed plugin for WordPress, which allows users to display TikTok content on their websites, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to do. While the impact is considered low, it could allow unauthorized changes to plugin settings or content.
Technical details
A Broken Access Control vulnerability (CWE-862) exists in the bPlugins Tiktok Feed plugin for WordPress in versions up to and including 1.0.24. The issue stems from incorrectly configured access control security levels, specifically a lack of proper authorization checks on certain functions. An authenticated attacker with Subscriber-level privileges can exploit this over the network to execute actions or modify settings that should be restricted to higher-privileged users. The vulnerability is resolved in version 1.0.25.
Affected products
- bPlugins Tiktok Feed n/a through 1.0.24
Timeline
- 2025-12-27: other: Reported by Nabil Irawan
- 2026-05-26: patched: Version 1.0.25 released
- 2026-05-26: disclosed: Published by Patchstack
- 2026-05-26: advisory: NVD published CVE-2026-24520