Target Video Easy Publish <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter
medium
The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img’ parameter in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an...
- CVSS:
- 6.4
- Affected:
- up to 3.8.8
- Fixed in:
- 3.8.9
- Disclosed:
- Jan 27, 2026
CVE-2025-8072 on NVD →
Target Video Easy Publish <= 3.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter
medium
The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 3.8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t...
- CVSS:
- 6.4
- Affected:
- up to 3.8.5
- Fixed in:
- 3.8.6
- Disclosed:
- Jun 17, 2025
CVE-2025-5237 on NVD →
Target Video Easy Publish <= 3.8.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The The Target Video Easy Publish plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated...
- CVSS:
- 5.4
- Affected:
- up to 3.8.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32688 on NVD →
Target Video Easy Publish [brid-video-easy-publish] < 3.8.4
unknown
[en] The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_override_yt shortcode in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Jan 29, 2025
CVE-2024-13561 on NVD →
Target Video Easy Publish <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via brid_override_yt Shortcode
medium
The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_override_yt shortcode in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...
- CVSS:
- 6.4
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.4
- Disclosed:
- Jan 28, 2025
CVE-2024-13561 on NVD →
Target Video Easy Publish [brid-video-easy-publish] < 3.8.4
unknown
[en] The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the resync_carousel(), seek_snapshot(), uploaded_cc(), and remove_cc() functions. This makes it possible for unauthenti...
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Jan 25, 2025
CVE-2024-12076 on NVD →
Target Video Easy Publish <= 3.8.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the resync_carousel(), seek_snapshot(), uploaded_cc(), and remove_cc() functions. This makes it possible for unauthenticated...
- CVSS:
- 6.1
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.4
- Disclosed:
- Jan 24, 2025
CVE-2024-12076 on NVD →
Target Video Easy Publish [brid-video-easy-publish] <= 3.8.5 (unfixed)
unknown
- Affected:
- up to 3.8.5
- Fix:
- No patched version reported
CVE-2025-32688 on NVD →
Target Video Easy Publish [brid-video-easy-publish] < 3.8.6
unknown
- Affected:
- up to 3.8.6
- Fixed in:
- 3.8.6
CVE-2025-5237 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database