# Jetpack VideoPress <= 3.6 - Missing Authorization to Restricted Video Playback via Subscription Plan ID

- **ID:** WPSEC-2026-0658
- **Plugin:** Jetpack VideoPress (`jetpack-videopress`), https://wordpress.org/plugins/jetpack-videopress/
- **Affected versions:** from 1.7 before 3.7
- **Fixed in:** 3.7 (Update to 3.7 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/jetpack-videopress
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0658/

## Description

The Jetpack VideoPress plugin for WordPress is vulnerable to unauthorized access of restricted videos in versions 1.7 up to, and including, 3.6. When issuing a video playback token, the plugin trusted the subscription plan ID sent with the request and granted access to any visitor with an active paid subscription to that plan, overriding the video's privacy setting and the subscription gate that actually applied to the post embedding the video, and it did not check that the embedding post was published. This makes it possible for attackers who hold a paid subscription to any plan on the site to obtain playback access to private videos and to videos gated behind other plans. Exploitation requires Jetpack's paid subscription features to be active on the site.

## References

- https://wpsec.com/vuln/WPSEC-2026-0658/
- https://plugins.svn.wordpress.org/jetpack-videopress/tags/3.7/
- https://wordpress.org/plugins/jetpack-videopress/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0658/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
