VYPR
Medium severity5.4NVD Advisory· Published Sep 9, 2025· Updated Apr 23, 2026

CVE-2025-32688

CVE-2025-32688

Description

Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Target Video Easy Publish: from n/a through <= 3.8.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WordPress Target Video Easy Publish plugin ≤3.8.9 has a missing authorization vulnerability allowing arbitrary shortcode execution, enabling remote code execution on affected sites.

The Target Video Easy Publish plugin for WordPress (brid-video-easy-publish) through version 3.8.9 contains a missing authorization vulnerability [1]. This flaw stems from insufficient access controls on certain plugin functions, allowing unauthenticated or low-privileged users to execute arbitrary WordPress shortcodes [1].

Exploitation requires no special privileges; an attacker only needs to send a crafted request to the WordPress installation [1]. The attack surface is broad because the plugin is widely deployed, and the vulnerability can be chained with other WordPress weaknesses to achieve remote code execution [1].

The impact is critical: a successful attacker can execute arbitrary PHP code on the target server, which may lead to full site compromise, data theft, malware injection, or use of the site in mass-exploit campaigns [1]. Given the simplicity of exploitation and the plugin's popularity, this vulnerability is expected to be widely targeted.

The plugin author has not released a patched version at the time of this advisory; users are urged to immediately disable or remove the plugin until an update is available [1]. If removal is not possible, consult a hosting provider or security professional for temporary mitigation steps.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.