Filtered by vendor Wpdevart
Subscribe
Filtered by product Youtube Embed\, Playlist And Popup
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-24002 | 1 Wpdevart | 1 Youtube Embed\, Playlist And Popup | 2024-11-21 | N/A | 5.9 MEDIUM |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart YouTube Embed, Playlist and Popup by WpDevArt plugin <= 2.6.3 versions. | |||||
CVE-2021-24464 | 1 Wpdevart | 1 Youtube Embed\, Playlist And Popup | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue. |