CVE · Medium

CVE-2021-24414 — Video Player for YouTube – Embed Videos Your Visitors Will Love to Watch [yt-player] < 1.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24414 Video Player for YouTube – Embed Videos Your Visitors Will Love to Watch [yt-player] < 1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.4 1.4 2021-09-22

CVE-2021-24414

The Video Player for YouTube plugin prior to version 1.4 fails to properly sanitize and validate shortcode parameters, enabling contributors and other low-privileged users to inject Cross-Site Scripting code that executes when pages containing the malicious shortcode are viewed.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.