plugin

Feeds For Youtube Vulnerabilities

10 known security issues reported for the Feeds For Youtube WordPress plugin. Most recent disclosed Jun 11, 2026.

5 medium

Running Feeds For Youtube on your site? Check whether your installed version is affected.

Scan your site free

Feeds for YouTube (YouTube video, channel, and gallery plugin) < 2.6.4 - Missing Authorization

medium

The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 2.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized act...

CVSS:
4.3
Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Jun 11, 2026

CVE-2026-1631 on NVD →

Feeds for YouTube (YouTube video, channel, and gallery plugin) [feeds-for-youtube] < 2.6.2

unknown

[en] The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.6.0 via the 'sby_check_wp_submit' AJAX action. This is due to insufficient sanitization of user-supplied data and the use of that data in a file operation. This makes it possible for unauthen...

Affected:
up to 2.6.2
Fixed in:
2.6.2
Disclosed:
Jan 17, 2026

CVE-2025-12002 on NVD →

Feeds for YouTube (YouTube video, channel, and gallery plugin) [feeds-for-youtube] <= 2.4.0 (unfixed)

unknown

[en] Missing Authorization vulnerability in Syed Balkhi Feeds for YouTube feeds-for-youtube allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Feeds for YouTube: from n/a through <= 2.4.0.

Affected:
up to 2.4.0
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-64635 on NVD →

Feeds for YouTube <= 2.4.0 - Missing Authorization

medium

The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.4.0
Fixed in:
2.6.1
Disclosed:
Nov 6, 2025

CVE-2025-64635 on NVD →

Feeds for YouTube (YouTube video, channel, and gallery plugin) [feeds-for-youtube] < 2.2.2

unknown

[en] The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This mak...

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Jul 11, 2024

CVE-2024-6256 on NVD →

Feeds for YouTube (YouTube video, channel, and gallery plugin) <= 2.2.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

CVSS:
6.4
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Jul 10, 2024

CVE-2024-6256 on NVD →

Feeds for YouTube (YouTube video, channel, and gallery plugin) [feeds-for-youtube] < 2.1.2

unknown

[en] The Feeds for YouTube for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with co...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Sep 14, 2023

CVE-2023-4841 on NVD →

Feeds for YouTube <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...

CVSS:
6.4
Affected:
up to 2.1
Fixed in:
2.1.2
Disclosed:
Sep 13, 2023

CVE-2023-4841 on NVD →

Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting

medium

Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 1.4.1
Fixed in:
1.4.2
Disclosed:
Jul 20, 2021

Feeds for YouTube (YouTube video, channel, and gallery plugin) [feeds-for-youtube] < 1.4.2

unknown

Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

Affected:
up to 1.4.2
Fixed in:
1.4.2
Disclosed:
Jul 20, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database