Cross-site Scripting Vulnerability in YouTube Showcase by Emarket-design
CVE-2025-58915

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 September 2025

What is CVE-2025-58915?

The YouTube Showcase plugin by Emarket-design contains a vulnerability that allows for Cross-site Scripting (XSS). This issue arises due to improper neutralization of user input during the generation of web pages. Exploiting this vulnerability can result in the execution of arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking or unauthorized actions on behalf of users. The affected versions span from an unspecified initial version to 3.5.0.

Affected Version(s)

YouTube Showcase <= 3.5.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ (Patchstack Bug Bounty Program)
.
CVE-2025-58915 : Cross-site Scripting Vulnerability in YouTube Showcase by Emarket-design