كل الثغرات
—
عالية
CVSS 7.4
Multiple vulnerabilities in Automatic YouTube Gallery
| المورّد | Plugins360 Labs |
|---|---|
| المنتج | Automatic YouTube Gallery |
| النسخ المتأثرة | < 2.9.0 |
| تاريخ الإبلاغ | 2026-08-10 |
| تاريخ الإفصاح | 2026-08-10 |
| الحالة | أصلحها المورّد |
Discovered and responsibly reported multiple security vulnerabilities in the WordPress plugin "Automatic YouTube Gallery" developed by Plugins360 Labs.
The reported issues included:
• Unauthenticated gallery manipulation vulnerabilities.
• YouTube API quota exhaustion issues.
• Pagination token validation weaknesses.
• URL parameter injection vulnerabilities.
• Thumbnail data handling weaknesses.
All findings were acknowledged by the vendor and fixed in version 2.9.0. The developer officially credited me in the plugin changelog for the responsible disclosure of these security issues.
The reported issues included:
• Unauthenticated gallery manipulation vulnerabilities.
• YouTube API quota exhaustion issues.
• Pagination token validation weaknesses.
• URL parameter injection vulnerabilities.
• Thumbnail data handling weaknesses.
All findings were acknowledged by the vendor and fixed in version 2.9.0. The developer officially credited me in the plugin changelog for the responsible disclosure of these security issues.