The plugin does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
1. Add a new post and add the payload there: [evp_embed_video url='" onerror=alert(/XSS/) "'] 2. Preview the post, and the XSS will trigger.
Lana Codes
Lana Codes
Yes
2022-11-22 (about 6 months ago)
2022-11-22 (about 6 months ago)
2022-12-05 (about 5 months ago)