Impact
The Lightweight and Responsive Youtube Embed plugin allows attackers to store JavaScript in the system, which is later rendered within web pages. This stored cross-site scripting flaw (CWE-79) could potentially result in cookie theft, session hijacking, or site defacement when other users view affected pages (inferred from typical XSS impacts). The impact is confined to the victim’s browser context, but it can be used to compromise multiple users on a site (inferred).
Affected Systems
WordPress installations running the Lightweight and Responsive Youtube Embed plugin (vendor wpszaki), versions up through 1.0.0. Any site that has added the plugin and uses its configuration or content inputs is vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and an EPSS score of less than 1%, indicating a low immediate exploitation probability, and it is not listed in the CISA KEV catalog. The description does not specify the attacker’s privileges required; however, it is inferred that the attacker must have the ability to insert script‑laden content into the plugin’s stored data, which would involve write access to the plugin’s settings or content fields (inferred). Once injected, the malicious script executes in the browsers of any user who views the impacted page.
OpenCVE Enrichment
EUVD