Open Redirect Vulnerability in WP YouTube Lyte by Frank Goossens
CVE-2025-66062

3.7LOW

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 November 2025

What is CVE-2025-66062?

The WP YouTube Lyte plugin by Frank Goossens contains an open redirect vulnerability that allows attackers to redirect users to untrusted sites. This flaw can be exploited to create phishing attacks, compromising user information and potentially leading to unauthorized access. Affected versions include all prior to and including 1.7.28. Users are encouraged to update to the latest version to mitigate this security risk.

Affected Version(s)

WP YouTube Lyte <= n/a

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.
CVE-2025-66062 : Open Redirect Vulnerability in WP YouTube Lyte by Frank Goossens