StreamWeasels YouTube Integration <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- Jul 28, 2025
CVE-2025-7811 on NVD →
StreamWeasels YouTube Integration [streamweasels-youtube-integration] < 1.3.7
unknown
[en] The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Nov 28, 2024
CVE-2024-11788 on NVD →
StreamWeasels YouTube Integration <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...
- CVSS:
- 6.4
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Nov 27, 2024
CVE-2024-11788 on NVD →
StreamWeasels YouTube Integration [streamweasels-youtube-integration] < 1.3.3
unknown
[en] The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 29, 2024
CVE-2024-10185 on NVD →
StreamWeasels YouTube Integration <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via sw-youtube-embed Shortcode
medium
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 28, 2024
CVE-2024-10185 on NVD →
StreamWeasels YouTube Integration [streamweasels-youtube-integration] < 1.1.4
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
CVE-2023-33999 on NVD →
StreamWeasels YouTube Integration [streamweasels-youtube-integration] < 1.4.1
unknown
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
CVE-2025-7811 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database