Executive brief
The Youtube Embed Plus plugin for WordPress, which allows site owners to easily embed and customize YouTube videos, contains a security flaw in its access control settings. An authenticated user with low-level permissions, such as a subscriber, could exploit this to perform actions or access information they should not be authorized to see. While the impact is considered limited, it could lead to unauthorized changes or data exposure within the plugin's functionality.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Youtube Embed Plus plugin for WordPress in versions up to and including 14.2.4. The flaw stems from incorrectly configured access control security levels, where the plugin fails to properly validate user permissions before executing certain functions. An attacker authenticated with low-level privileges (Subscriber or higher) can exploit this over the network to perform unauthorized actions or access restricted data. The issue is addressed in version 14.2.5 by implementing proper authorization checks.
Affected products
- embedplus Youtube Embed Plus <= 14.2.4
Timeline
- 2026-02-04: other: Vulnerability reported by researcher
- 2026-03-06: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published