Input validation vulnerability in Video Gallery – YouTube Playlist, Channel Gallery by YotuWP 1.3.12

The Video Gallery plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting in versions up to and including 1.3.12. This issue occurs because the plugin does not properly check the input it receives and fails to escape it before outputting it. This makes it possible for attackers with administrator-level access or higher to inject code on pages that will run whenever someone views the page. This issue only affects multi-site installations or installations where the “unfiltered_html” setting has been disabled.

Detected in:

Video Gallery – YouTube Playlist, Channel Gallery by YotuWP open vulnerable versions: >= * <= 1.3.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.