CVE-2025-66062 LOW

CVE-2025-66062: WordPress WP YouTube Lyte plugin <= 1.7.28 - Open Redirection vulnerability

Vendor Frank Goossens
Product WP YouTube Lyte
Weakness CWE-601 · Open redirect
Published November 21, 2025
Last update April 28, 2026

CVSS base score

3.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affects WP YouTube Lyte: from n/a through <= 1.7.28.

Explanation of Vulnerability in Simple Terms

02Summary

WP YouTube Lyte contains an open redirect vulnerability that allows an attacker to redirect users to an external website. The vulnerability requires user interaction—the victim must click a malicious link. The redirect can occur across different security contexts. This affects all versions up to and including 1.7.28.

What an attacker can do

03Attacker Capabilities

Redirect site visitors to a malicious external website via a crafted link.

Potential impact on your site

04Site Impact

Users may be tricked into visiting phishing or malware sites, damaging site reputation and user trust.

Conditions required to exploit

05Prerequisites

Victim must click a link containing the malicious redirect parameter.

Key dates

06Disclosure timeline

November 21, 2025 CVE published
April 28, 2026 Record updated