CVE-2026-1631Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-18); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-06-16: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-16: 105-1805-1906-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 #CVE-2026-1631: Critical Authorization Flaw in Feeds for #YouTube Plugin Puts 100K+ WordPress Sites at Risk + Video https://undercodetesting.com/cve-2026-1631-critical-authorization-flaw-in-feeds-for-youtube-plugin-puts-100k-wordpress-sites-at-risk-video/ Educational Purposes!

    Post summary

    The post alerts of a critical authorization flaw in the YouTube WordPress plugin that could affect over 100,000 sites; it provides basic technical detail but no exploit, patch, or evidence of active use.

    0000030
    615 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1631 🚨 Risk Level: Unknown 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1631 #CVE-2026-1631 #CVE  #Wordpress #CyberSecurity #InfoSec https://t.co/3K3cEZqjy1

    Post summary

    A brief alert announcing the new CVE‑2026‑1631 for WordPress, with no technical or exploit details provided.

    0000050
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1631 Unauthorized License Key Modification in Feeds for YouTube WordPress Plugin Before 2.6.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1631

    Post summary

    The text announces CVE-2026-1631, describing an unauthorized license key modification vulnerability in a WordPress plugin prior to version 2.6.4, but does not provide exploitation details or a patch.

    0000060
    4.0K followersView on X

Explore more