Loading vulnerability details…
CVSS v3.1
8.1
EPSS
0.22%
Published
May 15, 2025
Modified
Jan 5, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:HWeaknesses (CWE)
Affected Products (1)
References (2)