WordPress Plugin Vulnerabilities

YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server

Description

The plugin does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator.

The plugin was closed on wordpress.org on 25 July 2025 for a security issue and no fixed version exists, so affected sites must remove it rather than update.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Adem0n__
Submitter
Adem0n__
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 3 days ago)
Added
2026-09-10 (about 3 days ago)
Last Updated
2026-09-10 (about 3 days ago)

Other