Cross-site Scripting Vulnerability in Lightweight and Responsive Youtube Embed by WordPress
CVE-2025-31744

6.5MEDIUM

What is CVE-2025-31744?

The Lightweight and Responsive Youtube Embed plugin for WordPress has a vulnerability that arises from improper input sanitization during the web page generation process, leading to Stored Cross-site Scripting. This flaw can potentially allow malicious users to inject harmful scripts into web pages viewed by others, posing significant security risks to both site administrators and visitors.

Affected Version(s)

Lightweight and Responsive Youtube Embed <= 1.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SOPROBRO (Patchstack Alliance)
.