📦

youtube_embed\,_playlist_and_popup

Vendor: wpdevart

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.51% Exploit Prob.
Latest CVE CVE-2023-24002 Apr 06

Security Vulnerability Index

Page 1 / 1
5.9 CVSS

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart YouTube Embed, Playlist and Popup by WpDevArt plugin <= 2.6.3 versions.

EPSS: 0.39%
5.4 CVSS

The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.

EPSS: 0.62%