The “Offload Videos” plugin for WordPress, specifically versions older than 1.0.1, has been found to contain a serious security flaw. This vulnerability, identified as CVE-2024-6719, is a type of attack called Cross-Site Request Forgery (CSRF). In simple terms, this means that an attacker could trick a logged-in, low-privilege user into unknowingly changing the plugin’s settings. Imagine someone clicking a link or visiting a malicious webpage, and without them realizing it, their WordPress site’s video offloading settings are altered. This could lead to disruptions or unintended configurations on websites using the affected plugin.
CVE Details
- Product: Offload Videos WordPress plugin
- Published: May 15, 2025
- Severity: HIGH (CVSS score 8.1)
- Status: Analyzed
Affected Products
The vulnerability impacts the Offload Videos WordPress plugin. Specifically, any installations running versions prior to 1.0.1 are at risk. If you are using this plugin for Bunny.net or AWS S3 video offloading, it’s crucial to verify your current version.
Current Status
This vulnerability has been officially “Analyzed,” meaning its details and potential impact have been thoroughly reviewed and confirmed by security experts. This classification indicates that the threat is well-understood and actionable.
Severity Level
Rated as “HIGH” severity with a CVSS score of 8.1, this vulnerability poses a significant risk. A high-severity rating means that the flaw can be exploited relatively easily by attackers and could lead to substantial negative consequences for your website. While it requires a low-privilege user to be logged in and tricked into performing an action, the potential for unauthorized changes to critical plugin settings makes it a serious concern.
Possible Solutions
The most effective and straightforward solution is to update your Offload Videos WordPress plugin immediately. The developers have released a patch to address this CSRF vulnerability in version 1.0.1. Therefore, all users of the Offload Videos plugin should upgrade to version 1.0.1 or newer as soon as possible.
To update your plugin:
- Log in to your WordPress administration dashboard.
- Navigate to the ‘Plugins’ section.
- Locate the ‘Offload Videos’ plugin.
- If an update is available, click on the ‘Update Now’ link.
- Always back up your website before performing any updates.
If for any reason you cannot update immediately, consider implementing general web security best practices such as educating users about phishing attempts and unusual links, and ensuring that all users have strong, unique passwords. However, updating is the only definitive fix for this specific vulnerability.
References
https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/
https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/


