VulnerabilityModified
CVE-2021-24464
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site…
MEDIUM 5.4EPSS 0.62%
Does this matter?
Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.
Description
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wpdevart/youtube embed\, playlist and popup
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/531b3fac-48b9-4821-a3aa-4db073d43aaeExploit, Third Party Advisory
- https://wpscan.com/vulnerability/531b3fac-48b9-4821-a3aa-4db073d43aaeExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.