WP YouTube Lyte WordPress 插件在 1.7.31 版本之前,在渲染区块时未对 YouTube 嵌入区块的部分属性进行转义处理,而是直接将其输出为 HTML 属性。该漏洞可能导致角色权限低至“投稿者”(Contributor)的用户执行存储型跨站脚本(Stored XSS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP YouTube Lyte | 0 ~ 1.7.31 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89003 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview | |
| CVE-2026-84069 | WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php | |
| CVE-2026-81655 | Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields | |
| CVE-2026-82841 | UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migrati | |
| CVE-2026-85002 | EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes | |
| CVE-2026-86609 | Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription | |
| CVE-2026-86839 | Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via I | |
| CVE-2026-86841 | Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced O | |
| CVE-2026-89001 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing vi | |
| CVE-2026-96899 | Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script | |
| CVE-2026-89006 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import | |
| CVE-2026-89000 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run | |
| CVE-2026-96896 | Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deleti | |
| CVE-2026-96897 | Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Passw | |
| CVE-2026-92995 | Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file | |
| CVE-2026-92436 | Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via I | |
| CVE-2026-97319 | PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block | |
| CVE-2026-97227 | NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential |
No comments yet