CVE-2024-11788

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Embed YouTube content on your WordPress site. Easily embed a YouTube channel, shorts, gallery, feed, or live on your website.</p> <h3>The most advanced YouTube plugin for WordPress</h3> <p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/QQKCuSG2eHQ?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p>For over 5 years, <a href="https://www.streamweasels.com?utm_source=wordpress&amp;utm_medium=youtube-integration&amp;utm_campaign=readme" rel="nofollow ugc">StreamWeasels</a> have been helping thousands of WordPress websites <strong>embed YouTube channel, YouTube gallery, YouTube feed or YouTube live</strong>.</p> <p>StreamWeasels YouTube Integration is the latest and greatest plugin from StreamWeasels that <strong>takes YouTube Integration to the next level</strong>.</p> <p>This plugin allows you to <strong>display YouTube embeds anywhere on your website</strong>, based on YouTube Channel ID, YouTube Playlist or YouTube Live streams.</p> <h3>Display YouTube Videos by YouTube Channel, Shorts, Playlist, or Live</h3> <p>StreamWeasels YouTube Integration allows you to display YouTube shorts, YouTube video and YouTube live on your website from youtube.com based on YouTube Channel ID, Playlist or YouTube Live streams.</p> <ul> <li>Display upto 50 shorts from a specific YouTube <strong>Channel</strong>.</li> <li>Display upto 50 videos from a specific YouTube <strong>Channel</strong>.</li> <li>Display upto 50 videos from a specified YouTube <strong>Playlist</strong>.</li> <li>Display upto 50 YouTube live streams from a defined YouTube <strong>Channel</strong> list.</li> </ul> <h3>Display YouTube Shorts</h3> <p><iframe loading="lazy" title="Add YouTube shorts to WordPress (for FREE 2022) #shorts" width="750" height="422" src="https://www.youtube.com/embed/3Y1ab3k3ilw?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p> <h3>Layouts</h3> <p>The best part about StreamWeasels YouTube Integration is our range of layouts. As of our first release, StreamWeasels YouTube Integration allows you to embed YouTube channel content using a YouTube Wall layout. Display your YouTube content as it may appear directly on YouTube. Customise the number of YouTube tiles that display, the number of tiles in a row, the spacing, rounded borders and more.</p> <h3>Read More</h3> <p>If you want to learn more about StreamWeasels YouTube Integration, check out these links.</p> <ul> <li><a href="https://support.streamweasels.com/article/74-getting-started-with-youtube-integration" rel="nofollow ugc">YouTube Integration &#8211; Getting Started Guide</a></li> <li><a href="https://www.youtube.com/channel/UCo885jUiOeyhtHDFUbdx8rQ" rel="nofollow ugc">Check out our YouTube Guides</a></li> <li><a href="https://twitter.com/StreamWeasels" rel="nofollow ugc">Follow us on Twitter</a></li> <li><a href="https://discord.com/invite/HSwfPbm" rel="nofollow ugc">Join us on Discord</a></li> <li><a href="https://www.streamweasels.com/contact/" rel="nofollow ugc">Need Help? Get in touch!</a></li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
23.5K