Sceawere
Vulnerability Detail
CVE-2026-96895UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP YouTube Lyte Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- WP YouTube Lyte
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-09-27T06:17:22.707Z",
"pubdate": "2026-09-27T06:17:22.707Z",
"executiveSummary": "The WP YouTube Lyte WordPress plugin, specifically versions prior to 1.7.31, contains a critical security flaw involving improper neutralization of input during web page generation. This vulnerability is classified as Stored Cross-Site Scripting (XSS).\nThe issue arises from a failure to adequately sanitize or escape user-supplied attributes within YouTube embed blocks before they are rendered into the HTML document. This vulnerability impacts all installations using the affected plugin version.\nThe risk implication is significant, as it allows authenticated users with contributor-level privileges or higher to inject malicious JavaScript payloads into posts or pages. When these compromised pages are viewed by other users, including administrators, the malicious scripts execute within the context of their sessions.\nThe attacker capabilities include potential account takeover, session hijacking, unauthorized data exfiltration, and the modification of site content. Successful exploitation requires an attacker to possess the 'contributor' capability or higher on the target WordPress installation to inject the malicious embed code. No additional network-level access is required beyond standard web access to the administrative or post-editing interface.",
"technicalDetails": "The root cause of this vulnerability is improper output encoding when the plugin processes attributes assigned to YouTube embed blocks. Specifically, the plugin fails to sanitize user-provided attributes before embedding them into HTML attributes during the rendering process.\nIn WordPress, contributors can create and save posts but cannot publish them. The vulnerability allows these users to inject arbitrary JavaScript by embedding malicious content into the attributes of the YouTube embed shortcode or block. Because the plugin does not implement sufficient input validation or output escaping, the payload is stored directly in the database as part of the post content.\nThe attack flow proceeds as follows: First, an authenticated contributor identifies an injection point within the plugin's block or shortcode configuration. Second, the attacker crafts a payload designed to break out of the HTML attribute context—for example, using a sequence such as '\" onmouseover=\"alert(document.cookie)'. Third, the attacker inserts this crafted payload into the vulnerable attribute field. Fourth, the malicious code is saved into the WordPress database. Finally, when an unsuspecting user, such as an administrator, views the post in the front-end or back-end, the plugin dynamically injects the unescaped, malicious attribute into the document object model (DOM).\nOnce the DOM is rendered, the browser treats the injected string as part of the HTML element's attribute. The browser's parser interprets the attacker's characters as valid JavaScript event handlers or attributes, leading to the execution of the injected script in the context of the victim's browser session.\nThis Stored XSS is particularly dangerous because the script executes automatically whenever the page is rendered. Since the script runs in the context of the victim's session, it can access sensitive data stored in document.cookie, perform actions on behalf of the victim (such as creating new administrative accounts), or redirect users to malicious external domains. Because the vulnerability lies within the plugin's rendering logic, standard WordPress sanitization filters for contributors may be bypassed if the plugin fails to invoke them correctly during the block-to-HTML conversion phase.\nAffected versions include all releases of WP YouTube Lyte prior to 1.7.31. The vulnerability persists until the plugin is updated to the remediated version, which implements strict output escaping for all dynamically generated embed attributes."
}