Impact
The Simple Youtube Shortcode plugin permits a contributor‑level or higher user to insert arbitrary JavaScript into the 'id' attribute of the 'embed_youtube' shortcode. This insufficiently sanitized input is rendered without proper escaping, enabling a stored cross‑site script that executes in the browsers of any user who views the affected page. The resulting compromise can lead to session hijacking, defacement, or the delivery of phishing content, representing a moderate severity code‑execution risk from a client perspective.
Affected Systems
All installations of the Simple Youtube Shortcode WordPress plugin with a version of 1.1.3 or earlier are affected. The plugin, developed by matthewmarichiba, can be found in the WordPress plugin repository. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate severity. The EPSS score, below 1%, indicates a low probability of exploitation. The vulnerability is not included in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to have contributor‑level or higher authority within the WordPress site, after which the malicious script is stored in the database and will run whenever any user opens a page containing the shortcode. Attackers cannot wield the flaw remotely without prior authenticated access.
OpenCVE Enrichment