Executive brief
The VideoWhisper Paid Videochat Turnkey Site plugin for WordPress, which provides platforms for premium webcam services, contains a security flaw in its access control settings. This vulnerability allows unauthorized users to bypass intended security levels, potentially accessing features or information that should be restricted to paying members or administrators. While the impact is considered moderate, it could lead to unauthorized use of the service or exposure of internal site configurations.
Technical details
A Broken Access Control vulnerability (CWE-862) exists in the VideoWhisper.Com Paid Videochat Turnkey Site plugin for WordPress through version 7.3.23. The flaw stems from missing authorization checks in functions responsible for enforcing security levels, allowing unauthenticated remote attackers to bypass intended access restrictions. According to the CVSS vector, the attack is low complexity and requires no user interaction, though the impact is limited to a partial loss of confidentiality. The issue is resolved in version 7.3.24.
Affected products
- VideoWhisper.com Paid Videochat Turnkey Site <= 7.3.23
Timeline
- 2025-12-17: other: Reported by researcher ChuongVN
- 2026-05-26: advisory: Published by Patchstack and NVD
- 2026-05-26: patched: Version 7.3.24 released to address the issue