
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24535 is a Missing Authorization (Broken Access Control) vulnerability in the Automatic Featured Images from Videos WordPress plugin developed by WebDevStudios. It affects all versions up to and including 1.2.7, and was disclosed on January 23, 2026, with a patch released in version 1.2.8. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing certain privileged actions. Specifically, a function accessible to low-privileged authenticated users (Contributor or higher) lacks proper nonce token or capability checks, allowing those users to trigger actions intended for higher-privileged roles. This falls under OWASP Top 10 category A1: Broken Access Control. The vulnerability was discovered and reported by security researcher Nabil Irawan and disclosed via Patchstack on January 25, 2026 (Patchstack).
Successful exploitation allows an authenticated attacker with at least Contributor-level access to perform unauthorized actions within the WordPress site, resulting in a low integrity impact. There is no confidentiality or availability impact associated with this vulnerability. While the scope is limited to the affected WordPress installation, mass-exploit campaigns targeting WordPress plugins of this type are common, making even low-severity issues relevant for sites with untrusted contributor accounts (Patchstack).
The EPSS score for this vulnerability is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the wild. No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
wp-admin/admin-ajax.php or REST API endpoints associated with the automatic-featured-images-from-videos plugin from Contributor-level user accounts.wp_postmeta table) not initiated by editors or administrators.The vendor has released version 1.2.8 of the Automatic Featured Images from Videos plugin, which resolves this vulnerability. Site administrators should update the plugin immediately via the WordPress dashboard or by downloading the patched version from the WordPress plugin repository. As a temporary workaround, restricting Contributor-level user registration or removing untrusted Contributor accounts can reduce exposure. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."