PT-2026-54470 · WordPress · Youtube Showcase

·

CVE-2026-12923

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Youtube Showcase versions prior to 4.0.4
Description An arbitrary function call issue exists due to insufficient validation of the path parameter within the emd delete file() AJAX handler located in includes/common-functions.php. The input is processed via sanitize text field(), has the PLUGIN DIR substring removed, and is subsequently executed as a PHP function name through $sess name(). Because the handler lacks a current user can() check and relies solely on a nonce available on front-end pages with form shortcodes, authenticated users with Subscriber-level access or higher can trigger zero-argument PHP functions like phpinfo(), phpversion(), get defined vars(), or error get last(). This can lead to the disclosure of sensitive information and further system compromise.
Recommendations Update to a version newer than 4.0.3. As a temporary mitigation, restrict access to the emd delete file() AJAX handler or avoid using form shortcodes containing file fields until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12923

Affected Products

Youtube Showcase