Cross-site Scripting Vulnerability in Lightweight and Responsive Youtube Embed by WordPress
CVE-2025-31744
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 April 2025
What is CVE-2025-31744?
The Lightweight and Responsive Youtube Embed plugin for WordPress has a vulnerability that arises from improper input sanitization during the web page generation process, leading to Stored Cross-site Scripting. This flaw can potentially allow malicious users to inject harmful scripts into web pages viewed by others, posing significant security risks to both site administrators and visitors.
Affected Version(s)
Lightweight and Responsive Youtube Embed <= 1.0.0