VYPR
Medium severity4.3NVD Advisory· Published Jan 23, 2026· Updated Apr 28, 2026

CVE-2026-24535

CVE-2026-24535

Description

Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WordPress Automatic Featured Images from Videos plugin <=1.2.7 has a broken access control vulnerability allowing exploitation by unauthenticated attackers.

Vulnerability

Overview

The Automatic Featured Images from Videos plugin for WordPress versions 1.2.7 and earlier contains a missing authorization vulnerability [1]. The plugin fails to properly verify access control levels, allowing exploitation of incorrectly configured access control security levels.

Exploitation

This broken access control issue means that an unprivileged user, or even an unauthenticated attacker, may be able to execute actions that should require higher privileges. The vulnerability is reportedly used in mass-exploit campaigns, targeting thousands of websites regardless of their size or popularity [1]. No authentication is needed if the vulnerable function is exposed to unauthenticated users.

Impact

An attacker can exploit this vulnerability to perform unauthorized actions within the plugin's functionality, potentially leading to unauthorized modification of plugin settings or data. The official CVSS score of 4.3 indicates a medium severity with low likelyhood of exploitation according to the vendor [1].

Mitigation

The vulnerability has been patched in version 1.2.8 of the plugin. Users are strongly advised to update immediately. Those unable to update should seek assistance from their hosting provider or developer. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.