The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
PUBLISHED5.2
WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes
Problem type
- CWE-79 Cross-Site Scripting (XSS)
Affected products
Unknown
WP YouTube Lyte
< 1.7.31 - AFFECTED
References
GitHub Security Advisories
GHSA-xjqr-5587-cfwc
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube...
https://github.com/advisories/GHSA-xjqr-5587-cfwcThe WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-96895Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-96895",
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"dateUpdated": "2026-09-27T06:00:22.090Z",
"dateReserved": "2026-09-23T19:47:44.228Z",
"datePublished": "2026-09-27T06:00:22.090Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan",
"dateUpdated": "2026-09-27T06:00:22.090Z"
},
"title": "WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes",
"descriptions": [
{
"lang": "en",
"value": "The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks."
}
],
"affected": [
{
"vendor": "Unknown",
"product": "WP YouTube Lyte",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "1.7.31"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-79 Cross-Site Scripting (XSS)",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/15978f11-a7bd-41f0-94bf-069be4d03987/",
"tags": [
"exploit",
"vdb-entry",
"technical-description"
]
}
],
"credits": [
{
"lang": "en",
"value": "Dmitrii Ignatyev",
"type": "finder"
},
{
"lang": "en",
"value": "WPScan",
"type": "coordinator"
}
]
}
}
}