CVE-2024-10185

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Embed YouTube content on your WordPress site. Easily embed a YouTube channel, shorts, gallery, feed, or live on your website.</p> <h3>The most advanced YouTube plugin for WordPress</h3> <p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/QQKCuSG2eHQ?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p>For over 5 years, <a href="https://www.streamweasels.com?utm_source=wordpress&amp;utm_medium=youtube-integration&amp;utm_campaign=readme" rel="nofollow ugc">StreamWeasels</a> have been helping thousands of WordPress websites <strong>embed YouTube channel, YouTube gallery, YouTube feed or YouTube live</strong>.</p> <p>StreamWeasels YouTube Integration is the latest and greatest plugin from StreamWeasels that <strong>takes YouTube Integration to the next level</strong>.</p> <p>This plugin allows you to <strong>display YouTube embeds anywhere on your website</strong>, based on YouTube Channel ID, YouTube Playlist or YouTube Live streams.</p> <h3>Display YouTube Videos by YouTube Channel, Shorts, Playlist, or Live</h3> <p>StreamWeasels YouTube Integration allows you to display YouTube shorts, YouTube video and YouTube live on your website from youtube.com based on YouTube Channel ID, Playlist or YouTube Live streams.</p> <ul> <li>Display upto 50 shorts from a specific YouTube <strong>Channel</strong>.</li> <li>Display upto 50 videos from a specific YouTube <strong>Channel</strong>.</li> <li>Display upto 50 videos from a specified YouTube <strong>Playlist</strong>.</li> <li>Display upto 50 YouTube live streams from a defined YouTube <strong>Channel</strong> list.</li> </ul> <h3>Display YouTube Shorts</h3> <p><iframe loading="lazy" title="Add YouTube shorts to WordPress (for FREE 2022) #shorts" width="750" height="422" src="https://www.youtube.com/embed/3Y1ab3k3ilw?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p> <h3>Layouts</h3> <p>The best part about StreamWeasels YouTube Integration is our range of layouts. As of our first release, StreamWeasels YouTube Integration allows you to embed YouTube channel content using a YouTube Wall layout. Display your YouTube content as it may appear directly on YouTube. Customise the number of YouTube tiles that display, the number of tiles in a row, the spacing, rounded borders and more.</p> <h3>Read More</h3> <p>If you want to learn more about StreamWeasels YouTube Integration, check out these links.</p> <ul> <li><a href="https://support.streamweasels.com/article/74-getting-started-with-youtube-integration" rel="nofollow ugc">YouTube Integration &#8211; Getting Started Guide</a></li> <li><a href="https://www.youtube.com/channel/UCo885jUiOeyhtHDFUbdx8rQ" rel="nofollow ugc">Check out our YouTube Guides</a></li> <li><a href="https://twitter.com/StreamWeasels" rel="nofollow ugc">Follow us on Twitter</a></li> <li><a href="https://discord.com/invite/HSwfPbm" rel="nofollow ugc">Join us on Discord</a></li> <li><a href="https://www.streamweasels.com/contact/" rel="nofollow ugc">Need Help? Get in touch!</a></li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
23.5K