WordPress security by component
Video Gallery – YouTube Gallery, Playlist & Video Grid
Plugin description
Video Gallery – YouTube Gallery, Playlist & Video Grid is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 01, 2026; the highest CVE/CNA score is 8.1.
Plugin slug:
youtube-showcaseLatest vulnerability
CVE-2026-12923: Video Gallery – YouTube Gallery, Playlist & Video Grid: Sensitive information exposure
Video Gallery – YouTube Gallery, Playlist & Video Grid is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 4.0.3.
| Safe version |
|
||
|---|---|---|---|
| Jul 01, 2026 |
CVE-2026-12923
Video Gallery – YouTube Gallery, Playlist & Video Grid: Sensitive information exposure
Video Gallery – YouTube Gallery, Playlist & Video Grid is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 4.0.3.
|
> 4.0.3 |
CVE7.5
NVDPending
|
| Apr 15, 2026 |
CVE-2025-15636
YouTube Showcase: Cross-site scripting
YouTube Showcase is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.5.1.
|
3.5.2 |
CVE6.5
NVDPending
|
| Aug 28, 2025 |
CVE-2025-54731
YouTube Showcase: Code execution
YouTube Showcase is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Oct 03, 2023 |
CVE-2023-40558
Youtube Showcase: Cross-site request forgery
Youtube Showcase is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|