Jetpack VideoPress <= 3.6 - Missing Authorization to Restricted Video Playback via Subscription Plan ID

Medium 4.3 CWE-639Fixed in 3.7
ID
WPSEC-2026-0658
Plugin
Jetpack VideoPress (jetpack-videopress)
Affected
from 1.7 before 3.7
Remediation
Update to 3.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Jetpack VideoPress on WPSec AttackSurface
Fix released
Published

Description

The Jetpack VideoPress plugin for WordPress is vulnerable to unauthorized access of restricted videos in versions 1.7 up to, and including, 3.6. When issuing a video playback token, the plugin trusted the subscription plan ID sent with the request and granted access to any visitor with an active paid subscription to that plan, overriding the video's privacy setting and the subscription gate that actually applied to the post embedding the video, and it did not check that the embedding post was published. This makes it possible for attackers who hold a paid subscription to any plan on the site to obtain playback access to private videos and to videos gated behind other plans. Exploitation requires Jetpack's paid subscription features to be active on the site.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0