CVE-2021-24471 Information
Jun 07, 2022
cve
Description
The YouTube Embed WordPress plugin before 5.2.2 does not validate escape or sanitise some of its shortcode attributes leading to Stored XSS issues by 1. using w h controls cc_lang color language start stop or style parameter of youtube shortcode 2. by using style class rel target width height or alt parameter of youtube_thumb shortcode or 3. by embedding a video whose title or description contains XSS payload (if API key is configured).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://wpscan.com/vulnerability/a8ccb09a-9f8c-448f-b2d0-9b01c3a748ac
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: