2026-09-27 6:0CVE-2026-96895WPScan
PUBLISHED5.2

WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes

The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.

Problem type

  • CWE-79 Cross-Site Scripting (XSS)

Affected products

Unknown

WP YouTube Lyte

< 1.7.31 - AFFECTED

References

GitHub Security Advisories

GHSA-xjqr-5587-cfwc

The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube...

https://github.com/advisories/GHSA-xjqr-5587-cfwc

The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-96895
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-96895",
    "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
    "assignerShortName": "WPScan",
    "dateUpdated": "2026-09-27T06:00:22.090Z",
    "dateReserved": "2026-09-23T19:47:44.228Z",
    "datePublished": "2026-09-27T06:00:22.090Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "shortName": "WPScan",
        "dateUpdated": "2026-09-27T06:00:22.090Z"
      },
      "title": "WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes",
      "descriptions": [
        {
          "lang": "en",
          "value": "The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks."
        }
      ],
      "affected": [
        {
          "vendor": "Unknown",
          "product": "WP YouTube Lyte",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "1.7.31"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-79 Cross-Site Scripting (XSS)",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/15978f11-a7bd-41f0-94bf-069be4d03987/",
          "tags": [
            "exploit",
            "vdb-entry",
            "technical-description"
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Dmitrii Ignatyev",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "WPScan",
          "type": "coordinator"
        }
      ]
    }
  }
}