PT-2026-90964 · Undefined · Undefined
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YouTube Embed versions 10.0 through 10.3
Description
The plugin fails to perform authorization checks on an AJAX action, relying solely on a nonce printed on front-end pages. Additionally, it does not escape stored data before rendering, which allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS)—a technique where malicious scripts are permanently stored on the target server—via the
youram server parameter. These scripts execute in the session of any user who views the affected content, including administrators.Recommendations
Update YouTube Embed versions 10.0 through 10.3 to a newer version that contains a fix for this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined