The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amauri
Amauri tarteaucitron.io |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:amauri:tarteaucitron.io:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Amauri
Amauri tarteaucitron.io |
Wed, 18 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 18 Jun 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks. | |
| Title | tarteaucitron.io < 1.9.5 - Contributor+ Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-06-18T06:00:02.019Z
Updated: 2025-06-18T18:35:58.051Z
Reserved: 2025-05-19T12:57:59.033Z
Link: CVE-2025-4955
Updated: 2025-06-18T18:35:42.111Z
Status : Analyzed
Published: 2025-06-18T06:15:28.397
Modified: 2025-07-02T19:25:30.180
Link: CVE-2025-4955
No data.