Cross-Site Scripting Vulnerability in YouTube Showcase by Emarket-design
CVE-2025-15636

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2026

What is CVE-2025-15636?

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the YouTube Showcase plugin by Emarket-design. This flaw allows attackers to inject malicious scripts into web pages, which can then be executed in the browsers of users who visit the compromised pages. The vulnerability affects versions from 'not applicable' through 3.5.1 of the YouTube Showcase plugin, enabling potential exploitation without proper user interaction. It is crucial for users and administrators to assess their installations and apply necessary mitigations to avoid security risks.

Affected Version(s)

YouTube Showcase <= 3.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ | Patchstack Bug Bounty Program
.