Impact
The StreamWeasels YouTube Integration plugin contains a stored XSS flaw in the data‑uuid attribute. Because the plugin does not validate or escape user supplied values, an authenticated contributor or higher can embed malicious scripts that are saved to the site’s database. When any visitor loads a page containing the injected data‑uuid, the script runs in that visitor’s browser, giving the attacker the ability to steal session cookies, deface the page, or perform other client‑side attacks. This vulnerability is a classic CWE‑79 input error.
Affected Systems
WordPress sites running StreamWeasels YouTube Integration version 1.4.0 or earlier are affected. The vulnerability exists in the public JavaScript file that outputs the data‑uuid attribute for each YouTube embed. Users with contributor-level access or higher can exploit it. No other versions or components are noted as vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, indicating moderate severity, and an EPSS score of less than 1%, suggesting a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Exploitation requires authenticated access with contributor privileges and relies on victims visiting an affected page with the injected script. While the impact is limited to client‑side execution, it can still be leveraged for credential theft or site hijacking if users are unaware.
OpenCVE Enrichment
EUVD