PT-2024-28472 · WordPress · Playlist For Youtube Wordpress Plugin

Erdemstar

·

Published

2024-05-29

·

Updated

2024-10-03

·

CVE-2024-3937

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Playlist for Youtube WordPress plugin versions 1.32 and earlier
Description The issue concerns a Stored Cross-Site Scripting attack. High privilege users, such as admins, can exploit this even when the unfiltered html capability is disallowed, for example, in multisite setups. The vulnerability arises from the plugin's failure to sanitise and escape some of its settings.
Recommendations For versions 1.32 and earlier, update to a version that addresses this issue. As a temporary workaround, consider restricting the ability of high privilege users to modify plugin settings until a patch is available. Avoid using potentially malicious input in settings such as the Playlist Name and Video size.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-3937

Affected Products

Playlist For Youtube Wordpress Plugin