CVE-2025-0955

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 14, 2025
CWE ID 862

Summary

CVE-2025-0955 is a vulnerability affecting the VidoRev Extensions plugin for WordPress. This issue, present in versions up to and including 2.9.9.9.9.9.5, allows unauthenticated attackers to import arbitrary YouTube videos through a missing capability check on the 'vidorev_import_single_video' AJAX action. This vulnerability could potentially be exploited to upload unwanted content or gain unauthorized access to WordPress sites using this plugin. Site administrators are advised to update to the latest version of the plugin or consider disabling it until a patch is available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share