Feeds for YouTube WordPress Plugin Unauthorized License Key Modification Vulnerability

Vulnerability

A vulnerability exists in the Feeds for YouTube WordPress plugin, specifically in versions prior to 2.6.4. The issue arises from a missing capability check in the 'actions' function, allowing users with subscriber roles and above to delete the plugin's license key. This unauthorized modification could disrupt license management and associated functionalities.

Impact

Exploitation of this vulnerability allows for the unauthorized deletion of critical license information, potentially disrupting license management and associated features of the plugin.

Reproduction

To reproduce this vulnerability, first log into a WordPress site as a user with subscriber privileges. Once logged in, send a POST request to 'wp-admin/admin-ajax.php' without the necessary authorization. Include the 'action' parameter set to 'sby_recheck_connection' and any value for the 'license_key' parameter. The absence of a capability check allows the request to be processed, resulting in the deletion of the license key.

Remediation

Users are advised to update the Feeds for YouTube WordPress plugin to version 2.6.4 or later.

Added: May 18, 2026, 7:20 AM
Updated: May 18, 2026, 7:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.0
remediation
0.0
relevance
8.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.