Impact
Improper neutralization of user input during page rendering allows malicious JavaScript to be stored in the YouTube SimpleGallery plugin, creating a stored Cross‑Site Scripting vulnerability (CWE‑79). When visitors access the affected pages, the injected script executes in their browsers, potentially enabling an attacker to manipulate page content or trick users into performing unintended actions.
Affected Systems
All releases of Stian Andreassen’s YouTube SimpleGallery plugin up through version 2.0.6 are affected. Any WordPress installation running the plugin at or below this version while it is active is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate impact. The EPSS score of less than 1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to submit or edit content within the plugin interface to store the malicious script, after which the script runs in the browsers of site visitors viewing the affected content.
OpenCVE Enrichment
EUVD