Undefined · Undefined · CVE-2026-88793
**Name of the Vulnerable Software and Affected Versions**
YouTube Embed versions 10.0 through 10.3
**Description**
The plugin fails to perform authorization checks on an AJAX action, relying solely on a nonce printed on front-end pages. Additionally, it does not escape stored data before rendering, which allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS)—a technique where malicious scripts are permanently stored on the target server—via the `youram server` parameter. These scripts execute in the session of any user who views the affected content, including administrators.
**Recommendations**
Update YouTube Embed versions 10.0 through 10.3 to a newer version that contains a fix for this issue.