Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode
medium
The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' shortcode. This is due to insufficient input sanitization and output escaping on attachment titles referenced by the shortcode's image field: EMD_MB_Helper::image_info() r...
- CVSS:
- 6.4
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Aug 15, 2026
CVE-2026-15790 on NVD →
Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter
high
The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied value is passed through sanitize_text_field()...
- CVSS:
- 7.5
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.4
- Disclosed:
- Jun 30, 2026
CVE-2026-12923 on NVD →
Video Gallery – YouTube Gallery & Responsive Video Playlist <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Video Gallery – YouTube Gallery & Responsive Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Apr 15, 2026
CVE-2025-15636 on NVD →
Multiple Plugins by eMarket Design <= Various Versions - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
Multiple plugins for WordPress by by eMarket Design are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.1
- Disclosed:
- Sep 23, 2025
CVE-2025-58915 on NVD →
YouTube Showcase – Responsive YouTube Video Gallery Plugin for WordPress [youtube-showcase] < 3.5.2
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase allows Object Injection. This issue affects YouTube Showcase: from n/a through 3.5.1.
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.2
- Disclosed:
- Aug 28, 2025
CVE-2025-54731 on NVD →
YouTube Showcase <= 3.5.1 - Unauthenticated PHP Object Injection
high
The YouTube Showcase plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present...
- CVSS:
- 8.1
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Aug 25, 2025
CVE-2025-54731 on NVD →
Multiple Plugins by emarket-design <= Multiple Versions - Unauthenticated Limited Remote Code Execution
high
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible fo...
- CVSS:
- 8.1
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Aug 5, 2025
CVE-2025-8420 on NVD →
YouTube Showcase – Responsive YouTube Video Gallery Plugin for WordPress [youtube-showcase] < 3.4.0
unknown
[en] The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including, 3.3.6. This makes it possible for unau...
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
- Disclosed:
- May 21, 2024
CVE-2024-3268 on NVD →
YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation
medium
The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including, 3.3.6. This makes it possible for unauthent...
- CVSS:
- 5.3
- Affected:
- up to 3.3.6
- Fixed in:
- 3.4.0
- Disclosed:
- May 20, 2024
CVE-2024-3268 on NVD →
YouTube Showcase – Responsive YouTube Video Gallery Plugin for WordPress [youtube-showcase] < 3.3.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3.3.5 versions.
- Affected:
- up to 3.3.6
- Fixed in:
- 3.3.6
- Disclosed:
- Oct 3, 2023
CVE-2023-40558 on NVD →
Video Gallery & Management <= 3.3.5 - Cross-Site Request Forgery
medium
The Video Gallery & Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.5. This is due to missing nonce validation on the emd_show_forms_lite_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged r...
- CVSS:
- 4.3
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.6
- Disclosed:
- Aug 16, 2023
CVE-2023-40558 on NVD →
YouTube Showcase – Responsive YouTube Video Gallery Plugin for WordPress [youtube-showcase] < 3.5.1
unknown
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
CVE-2025-58915 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database