CVE-2024-11354
21.11.2024, 11:15
The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the del_ytsingvid() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete single playlists.Enginsight
Vendor | Product | Version |
---|---|---|
codelizar | ultimate_youtube_video_\&_shorts_player_with_vimeo | 𝑥 ≤ 3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References