Impact
The WP YouTube Video Optimizer plugin contains a stored XSS weakness in the ib_youtube shortcode. Unsanitized and unescaped attribute values can be stored in the database, and the plugin later outputs them to any page that parses the shortcode. An attacker with contributor or higher privileges can therefore insert malicious scripts that run in the browsers of any user who views a post or page with the affected content. This can lead to session hijacking, credential theft, or defacement. The weakness corresponds to CWE-79.
Affected Systems
All installations of the WP YouTube Video Optimizer plugin with a version equal to or older than 1.2 are affected. The plugin is distributed by the vendor Measuremarketing and is used within WordPress sites. No further version details are listed by the CNA.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity and the EPSS score of less than 1% suggests a low but present likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. Attackers need authenticated contributor‑level access to create or edit content that contains the ib_youtube shortcode; the code then runs for any site visitor. While the chance of widespread exploitation may be low, once present it can compromise the trust and integrity of the affected sites.
OpenCVE Enrichment
EUVD