The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin prior to 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wpdevart youtube embed\\, playlist and popup |