A vulnerability, which was classified as critical , was found in Feeds for YouTube Plugin up to 2.6.3 on WordPress. The affected element is the function actions of the component License Key Handler . Such manipulation leads to missing authorization. This vulnerability is documented as CVE-2026-1631 . The attack can be executed remotely. There is not any exploit available. You should upgrade the affected component.