Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1.
Published: 2025-04-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Stored Cross‑Site Scripting flaw caused by improper neutralization of input during web page generation in the Video Playlist For YouTube plugin. An attacker who can inject a malicious string into a playlist entry will have that string stored and later rendered as part of the page, allowing the attacker’s script to execute in the browsers of any visitor. This can lead to session hijacking, credential theft, defacement, or the execution of more complex client‑side attacks. The weakness is classified as CWE‑79, a classic input‑validation issue. The vulnerability could let an attacker perform a variety of attacks in the context of the logged‑in user who views the compromised page.

Affected Systems

The flaw affects all WordPress installations that use the Galaxy Weblinks Video Playlist For YouTube plugin version 6.7.1 or earlier. Because the plugin can be installed on any WordPress site, a large number of publicly accessible websites are potentially exposed. The plugin stores playlist entries in the WordPress database and renders them on the front‑end without sanitizing user‑supplied data.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests the probability of exploitation is currently low. The vulnerability is not included in the CISA KEV catalog. Likely attack vectors are via the public web: a user with permission to create or edit playlists can inject the payload. Once injected, the payload is served to all visitors of that playlist page, potentially escalating the attack surface.

Generated by OpenCVE AI on May 1, 2026 at 11:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Video Playlist For YouTube plugin to the latest version (6.8 or higher) to apply the vendor‑supplied fix for the stored XSS flaw
  • If an upgrade is not yet possible, identify and delete any playlist items that contain suspicious or untrusted content, and limit who can edit or add items to maintain strict access controls
  • Implement general WordPress best practices: Sanitize all user input on the front‑end, use a strong content security policy to block or restrict execution of untrusted scripts, and monitor the site for signs of injected malicious code

Generated by OpenCVE AI on May 1, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9848 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube allows Stored XSS. This issue affects Video Playlist For YouTube: from n/a through 6.6.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1.
Title WordPress Video Playlist For YouTube plugin <= 6.8 - Cross Site Scripting (XSS) vulnerability WordPress Video Playlist For YouTube plugin <= 6.7.1 - Cross Site Scripting (XSS) vulnerability

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.8.
Title WordPress Video Playlist For YouTube plugin <= 6.7.1 - Cross Site Scripting (XSS) vulnerability WordPress Video Playlist For YouTube plugin <= 6.8 - Cross Site Scripting (XSS) vulnerability
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube allows Stored XSS. This issue affects Video Playlist For YouTube: from n/a through 6.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1.
Title WordPress Video Playlist For YouTube plugin <= 6.6 - Cross Site Scripting (XSS) vulnerability WordPress Video Playlist For YouTube plugin <= 6.7.1 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 04 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube allows Stored XSS. This issue affects Video Playlist For YouTube: from n/a through 6.6.
Title WordPress Video Playlist For YouTube plugin <= 6.6 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:18.260Z

Reserved: 2025-04-04T10:01:19.451Z

Link: CVE-2025-32183

cve-icon Vulnrichment

Updated: 2025-04-04T18:28:17.919Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:27.770

Modified: 2026-04-28T19:31:30.127

Link: CVE-2025-32183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:15:15Z

Weaknesses