WordPress Automatic YouTube Gallery plugin <= 2.3.3 - Broken Access Control vulnerability
CVE-2023-41866
4.3MEDIUM
What is CVE-2023-41866?
A vulnerability exists in the Automatic YouTube Gallery plugin, a product by Plugins360, whereby incorrectly configured access control settings could allow unauthorized users to exploit the application. The issue primarily affects versions from n/a up to 2.3.3, posing significant security concerns for users relying on this plugin to manage their YouTube galleries.
Affected Version(s)
Automatic YouTube Gallery <= 2.3.3