WordPress Plugin Vulnerabilities

Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link

Description

The plugin does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
testoun
Submitter
testoun
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 23 days ago)
Added
2026-08-10 (about 23 days ago)
Last Updated
2026-08-10 (about 23 days ago)

Other