Impact
The WP YouTube Lyte plugin fails to escape certain attributes of YouTube embed blocks before rendering them in HTML attributes. Consequently, a user with contributor or higher privileges can inject arbitrary JavaScript that is stored and executed for every site visitor, allowing attacker‑controlled code to run in the context of the site’s users.
Affected Systems
WordPress sites that use the WP YouTube Lyte plugin with a version older than 1.7.31 are affected. Any WordPress installation where a contributor, author, or higher role can edit embed blocks is vulnerable.
Risk and Exploitability
Because the flaw requires only a contributor role, it is relatively easy for an attacker with existing website access to exploit. The stored nature of the XSS means the malicious payload persists until the plugin is updated or the embed block is removed. While no CVSS score or EPSS metric is available, the combination of ubiquitous plugin use and the ability to inject persistent scripts raises the severity to high. The vulnerability is not listed in the CISA KEV catalog, indicating that it may not yet have been the target of known exploits, but the potential impact on user accounts and site integrity is significant.
OpenCVE Enrichment