← WordPress Vulnerabilities
WordPress security by component

YouTube Embed

YouTube Embed embeds YouTube videos and playlists into WordPress content.

YouTube Embed (youtube-embed) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Sep 13, 2026; the highest published CVSS base score is 8.8.

Plugin slug: youtube-embed

CVE-2026-88793: YouTube Embed lets unauthenticated callers store scripts through a public AJAX nonce

YouTube Embed 10.0 through 10.3 exposes an AJAX action without an authorization check and prints its nonce on every front-end page. An unauthenticated attacker can obtain that nonce, submit attacker-controlled data for storage, and have the unescaped value execute as a web script when affected content is viewed, including in an administrator's session. The authoritative export does not identify the AJAX action, storage field, rendered context, or parameter names.

PublishedSep 13, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for youtube-embed
Safe version
Sep 13, 2026 CVE-2026-88793
YouTube Embed lets unauthenticated callers store scripts through a public AJAX nonce
YouTube Embed 10.0 through 10.3 exposes an AJAX action without an authorization check and prints its nonce on every front-end page. An unauthenticated attacker can obtain that nonce, submit attacker-controlled data for storage, and have the unescaped value execute as a web script when affected content is viewed, including in an administrator's session. The authoritative export does not identify the AJAX action, storage field, rendered context, or parameter names.
See mitigation notes
CVE8.8
NVDPending
Dec 24, 2025 CVE-2025-68599
YouTube Embed: Cross-site scripting
YouTube Embed is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Apr 09, 2025 CVE-2025-31008
YouTube Embed: Cross-site scripting
YouTube Embed is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Aug 16, 2021 CVE-2021-24471
YouTube Embed: Cross-site scripting
YouTube Embed is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Aug 31, 2015 CVE-2015-6535
Youtube Embed: Cross-site scripting
Youtube Embed is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD3.5