Impact
Improper neutralization of input during web page generation allows a stored cross-site scripting flaw in the Easy YouTube Gallery plugin. An attacker who can submit data that the plugin stores can cause arbitrary JavaScript to execute in browsers of visitors, potentially leading to phishing, credential theft, defacement, or other malicious client‑side actions.
Affected Systems
The vulnerability affects Aleksandar Urošević Easy YouTube Gallery plugin for WordPress version 1.0.4 and earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the current data set. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely exploit it by injecting payloads into the plugin’s content fields that are stored and later rendered for site visitors.
OpenCVE Enrichment
EUVD