WordPress Plugin Vulnerabilities
YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server
Description
The plugin does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator.
The plugin was closed on wordpress.org on 25 July 2025 for a security issue and no fixed version exists, so affected sites must remove it rather than update.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Adem0n__
Submitter
Adem0n__
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-10 (about 3 days ago)
Added
2026-09-10 (about 3 days ago)
Last Updated
2026-09-10 (about 3 days ago)