Cross-Site Scripting Vulnerability in YouTube Embed Plugin for WordPress
CVE-2015-6535

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
31 August 2015

What is CVE-2015-6535?

A cross-site scripting (XSS) vulnerability exists in the YouTube Embed plugin for WordPress prior to version 3.3.3. This security flaw allows remote administrators to inject arbitrary web script or HTML through the Profile name field (specifically the youtube_embed_name parameter). Exploiting this vulnerability could enable malicious actors to compromise the integrity of WordPress sites, posing a significant risk to both administrators and end users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.