Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator. | |
| Title | YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-13T20:06:36.557Z
Reserved: 2026-09-10T08:09:26.182Z
Link: CVE-2026-88793
No data.
Status : Received
Published: 2026-09-13T21:17:02.197
Modified: 2026-09-13T21:17:02.197
Link: CVE-2026-88793
No data.
OpenCVE Enrichment
No data.
No weakness.