Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Adem0N

#32407of 57,548
8.8Total CVSS
Vulnerabilities · 1
PT-2026-90964
8.8
2026-09-13
Undefined · Undefined · CVE-2026-88793
**Name of the Vulnerable Software and Affected Versions** YouTube Embed versions 10.0 through 10.3 **Description** The plugin fails to perform authorization checks on an AJAX action, relying solely on a nonce printed on front-end pages. Additionally, it does not escape stored data before rendering, which allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS)—a technique where malicious scripts are permanently stored on the target server—via the `youram server` parameter. These scripts execute in the session of any user who views the affected content, including administrators. **Recommendations** Update YouTube Embed versions 10.0 through 10.3 to a newer version that contains a fix for this issue.