Stored Cross-Site Scripting Vulnerability in Responsive Video Embedder Plugin for WordPress
CVE-2026-8877
6.4MEDIUM
What is CVE-2026-8877?
The Responsive Video Embedder plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. Specifically, the 'rem_video' shortcode allows user-supplied attributes, such as 'id' and 'list', to be injected directly into the HTML iframe's src attribute. This flaw enables authenticated users with contributor-level access or above to introduce arbitrary web scripts into pages. As a result, these scripts execute when any user visits the compromised page, potentially leading to malicious activities and data exposure.
Affected Version(s)
Responsive Video Embedder 0 <= 0.1