UNKNOWN (0.0)
    Plugin

    Stored Cross-Site Scripting Vulnerability in Show YouTube Video WordPress Plugin

    Published Date: 3/7/2026
    CVE ID: CVE-2026-1825

    Summary

    The Show YouTube Video plugin for WordPress suffers from a stored cross-site scripting (XSS) vulnerability. This issue affects all plugin versions up to and including 1.1, enabling authenticated users with contributor-level access or higher to inject malicious scripts via the 'syv' shortcode.

    Vulnerability Details

    The vulnerability in the Show YouTube Video plugin arises from inadequate sanitization and insufficient escaping of user-supplied attributes in the 'syv' shortcode. This weakness permits an attacker with contributor-level access to upload malicious script content. When displayed on a web page, this script will execute within the context of the browser of any user who views the affected page, potentially allowing the attacker to conduct actions such as session hijacking, defacement, or phishing for user credentials. The absence of proper input validation and output escaping poses a significant risk, particularly in multi-user environments where users have elevated permissions. It's crucial for plugin developers to implement rigorous checks and escapes to prevent such script injection attacks. Ensuring content is handled safely at every stage of rendering is key to maintaining the security and integrity of web applications.

    Recommendations

    To mitigate this vulnerability, ensure rigorous input validation and output escaping for all attributes processed by the plugin's 'syv' shortcode. Restrict contributor-level access, routinely audit user actions, and educate users on best security practices. Consider using the WordPress capabilities API to fine-tune user permissions and restrict shortcode execution to trusted roles.

    Available Fixes

    Last Updated: 3/10/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More