Offload Videos WordPress Plugin Cross-Site Request Forgery Vulnerability (CVE-2024-6719) — High Severity

The “Offload Videos” plugin for WordPress, specifically versions older than 1.0.1, has been found to contain a serious security flaw. This vulnerability, identified as CVE-2024-6719, is a type of attack called Cross-Site Request Forgery (CSRF). In simple terms, this means that an attacker could trick a logged-in, low-privilege user into unknowingly changing the plugin’s settings. Imagine someone clicking a link or visiting a malicious webpage, and without them realizing it, their WordPress site’s video offloading settings are altered. This could lead to disruptions or unintended configurations on websites using the affected plugin.

CVE Details

  • Product: Offload Videos WordPress plugin
  • Published: May 15, 2025
  • Severity: HIGH (CVSS score 8.1)
  • Status: Analyzed

Affected Products

The vulnerability impacts the Offload Videos WordPress plugin. Specifically, any installations running versions prior to 1.0.1 are at risk. If you are using this plugin for Bunny.net or AWS S3 video offloading, it’s crucial to verify your current version.

Current Status

This vulnerability has been officially “Analyzed,” meaning its details and potential impact have been thoroughly reviewed and confirmed by security experts. This classification indicates that the threat is well-understood and actionable.

Severity Level

Rated as “HIGH” severity with a CVSS score of 8.1, this vulnerability poses a significant risk. A high-severity rating means that the flaw can be exploited relatively easily by attackers and could lead to substantial negative consequences for your website. While it requires a low-privilege user to be logged in and tricked into performing an action, the potential for unauthorized changes to critical plugin settings makes it a serious concern.

Possible Solutions

The most effective and straightforward solution is to update your Offload Videos WordPress plugin immediately. The developers have released a patch to address this CSRF vulnerability in version 1.0.1. Therefore, all users of the Offload Videos plugin should upgrade to version 1.0.1 or newer as soon as possible.

To update your plugin:

  1. Log in to your WordPress administration dashboard.
  2. Navigate to the ‘Plugins’ section.
  3. Locate the ‘Offload Videos’ plugin.
  4. If an update is available, click on the ‘Update Now’ link.
  5. Always back up your website before performing any updates.

If for any reason you cannot update immediately, consider implementing general web security best practices such as educating users about phishing attempts and unusual links, and ensuring that all users have strong, unique passwords. However, updating is the only definitive fix for this specific vulnerability.

References

https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/

https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.