CVE-2026-39485
Received Received - Intake
Missing Authorization in Youtube Embed Plus Plugin

Publication date: 2026-04-08

Last updated on: 2026-04-10

Assigner: Patchstack

Description
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-08
Last Modified
2026-04-10
Generated
2026-05-07
AI Q&A
2026-04-08
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
embedplus youtube_embed_plus to 14.2.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2026-39485 is a Broken Access Control vulnerability found in the WordPress Youtube Embed Plus plugin versions up to and including 14.2.4.

This vulnerability arises from missing authorization, authentication, or nonce token checks in certain plugin functions, which allows unprivileged users to perform actions that normally require higher privileges.

It is classified under the OWASP Top 10 category A1: Broken Access Control and has a CVSS severity score of 4.3, indicating a low severity impact.


How can this vulnerability impact me? :

This vulnerability allows users with only subscriber-level privileges to exploit the plugin and perform unauthorized actions that require higher privileges.

Although the severity is considered low, such vulnerabilities can be used in mass-exploit campaigns targeting thousands of websites indiscriminately.

If exploited, it could lead to unauthorized changes or actions within the affected WordPress site, potentially compromising site integrity or functionality.

The issue was fixed in version 14.2.5, so updating to this or later versions is strongly recommended to mitigate the risk.


How can this vulnerability be detected on my network or system? Can you suggest some commands?

The CVE-2026-39485 vulnerability is a broken access control issue in the Youtube Embed Plus WordPress plugin versions up to 14.2.4. Detection involves identifying if your WordPress site is running a vulnerable version of this plugin.

Since the vulnerability allows unprivileged users (subscriber-level) to perform unauthorized actions, monitoring for unusual privilege escalation attempts or unauthorized actions in the plugin's functionality could indicate exploitation.

Specific commands are not provided in the available resources. However, you can check the installed plugin version using WP-CLI with the command: `wp plugin list` and verify if 'youtube-embed-plus' is installed and its version is less than or equal to 14.2.4.

Additionally, reviewing web server logs for suspicious requests targeting the Youtube Embed Plus plugin endpoints or unusual POST requests from subscriber-level users may help detect exploitation attempts.


What immediate steps should I take to mitigate this vulnerability?

The primary and recommended mitigation step is to update the Youtube Embed Plus WordPress plugin to version 14.2.5 or later, where the vulnerability has been fixed.

If immediate updating is not possible, consider restricting subscriber-level user capabilities temporarily to limit potential exploitation.

Using automatic update tools such as Patchstack's automatic updates for vulnerable plugins can facilitate rapid mitigation.

Regularly monitor your site for suspicious activity and ensure that your WordPress installation and all plugins are kept up to date to reduce exposure to similar vulnerabilities.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The provided information does not specify any direct impact of the CVE-2026-39485 vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart