← WordPress Vulnerabilities
WordPress security by component

Video Player for YouTube

Video Player for YouTube embeds and displays YouTube videos using a configurable video player.

Video Player for YouTube (video-player-for-youtube) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 6.8.

Plugin slug: video-player-for-youtube

CVE-2026-84937: Video Player for YouTube permits Contributor-level SQL injection

Video Player for YouTube before 2.1.0 uses Contributor-controlled input in an SQL statement without adequate sanitization or escaping. A Contributor or higher can inject SQL and read arbitrary database data.

PublishedSep 05, 2026
Known safe version2.1.0
Published vulnerabilities for video-player-for-youtube
Safe version
Sep 05, 2026 CVE-2026-84937
Video Player for YouTube permits Contributor-level SQL injection
Video Player for YouTube before 2.1.0 uses Contributor-controlled input in an SQL statement without adequate sanitization or escaping. A Contributor or higher can inject SQL and read arbitrary database data.
2.1.0
CVE6.8
NVDPending
Oct 25, 2021 CVE-2021-24414
Video Player for YouTube: Cross-site scripting
Video Player for YouTube is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4