Input validation vulnerability in YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin 10.3

The YouTube Embed plugin on WordPress has a security issue that allows hackers to insert harmful code through the ‘instance’ parameter. This can affect all versions up to 10.3 because the plugin does not properly filter or protect the input and output of the code. This means that anyone with Contributor-level access or higher can add malicious scripts to pages, which will run whenever a user visits that page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.