Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wp Youtube Lyte Project Subscribe
Filtered by product Wp Youtube Lyte
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24419 1 Wp Youtube Lyte Project 1 Wp Youtube Lyte 2021-07-15 3.5 LOW 4.8 MEDIUM
The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues.