Unauthorized Access Vulnerability in VidoRev Extensions Plugin for WordPress
CVE-2025-0955
5.3MEDIUM
Key Information:
- Vendor
- Beeteam368
- Status
- Vidorev Extensions
- Vendor
- CVE Published:
- 14 March 2025
Summary
The VidoRev Extensions plugin for WordPress is susceptible to unauthorized access due to a lack of proper capability checks on the 'vidorev_import_single_video' AJAX action. This vulnerability allows unauthenticated attackers to import arbitrary YouTube videos, potentially leading to the manipulation of content on sites using the affected plugin versions.
Affected Version(s)
VidoRev Extensions * <= 2.9.9.9.9.9.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lucio Sá