Impact
An attacker can inject malicious JavaScript into the YouTube Embed plugin, causing it to persist in the site’s database and execute automatically when any user views affected pages. This stored XSS flaw permits an adversary to compromise confidentiality, integrity, or availability of site content by hijacking user sessions, stealing credentials, or modifying page content. The flaw is a classic insufficiency of input sanitisation, categorized as CWE‑79.
Affected Systems
The vulnerability affects the Embeds For YouTube Plugin Support: YouTube Embed plugin for WordPress up to and including version 5.3.1. No other products or versions are presently listed as affected.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity, while the EPSS score of less than 1 % suggests exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be local or administrative; an attacker with the ability to add or edit content handled by the plugin could embed the malicious code and have it stored for all visitors. Because the flaw is stored, once injected it will affect any user who views the compromised page.
OpenCVE Enrichment
EUVD