![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-41866 – WordPress Automatic YouTube Gallery plugin <= 2.3.3 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-41866
05 Sep 2023 — Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic YouTube Gallery: from n/a through 2.3.3. The Automatic YouTube Gallery plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on the ajax_callback_save_api_key and ajax_callback_delete_cache functions in versions up to, and including, 2.3.3. This makes it possible for authenti... • https://patchstack.com/database/wordpress/plugin/automatic-youtube-gallery/vulnerability/wordpress-automatic-youtube-gallery-plugin-2-3-3-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •