What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in James Lao's Simple Video Embedder plugin <= 2.2 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in James Lao's Simple Video Embedder plugin <= 2.2 on WordPress.
Explanation of Vulnerability in Simple Terms
Simple Video Embedder versions 2.2 and earlier contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts into video embed content. When other users view the affected page, the injected script executes in their browser, potentially allowing the attacker to steal session tokens, modify page content, or perform actions on behalf of the victim.
What an attacker can do
Inject malicious JavaScript that executes when other users view embedded videos.
Potential impact on your site
Visitors to pages with embedded videos may have their sessions hijacked or see malicious content injected by attackers with user accounts.
Conditions required to exploit
Attacker must have a WordPress user account with low-level privileges (e.g., contributor or subscriber).
Key dates
External resources
Related vulnerabilities