Impact
The vulnerability is an improper neutralization of input during web page generation that allows attackers to store malicious scripts in the Lightweight and Responsive Youtube Embed plugin. Once stored, the script executes in the browser of any visitor who views the related content, enabling actions such as cookie theft, session hijacking, or defacement. The weakness aligns with CWE‑79, which describes unsanitized user input leading to XSS.
Affected Systems
WordPress sites running the wpszaki Lightweight and Responsive Youtube Embed plugin, version 1.0.0 or earlier. The issue is reported for all releases from the initial version through that maximum.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to insert a malicious payload through the plugin’s interface; authentication or elevated privileges may be necessary, although the description does not specify required permissions.
OpenCVE Enrichment
EUVD