CVE-2026-88793
YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator.
| Vendor | unknown |
| Product | youtube embed |
| Published | Sep 13, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown youtube embed
Be the first to know when new high vulnerabilities affecting unknown youtube embed are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / YouTube Embed
10.0 โค 10.3
References
Credits
Adem0n__ WPScan