The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
History

Wed, 02 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Amauri
Amauri tarteaucitron.io
Weaknesses CWE-79
CPEs cpe:2.3:a:amauri:tarteaucitron.io:*:*:*:*:*:wordpress:*:*
Vendors & Products Amauri
Amauri tarteaucitron.io

Wed, 18 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Jun 2025 06:15:00 +0000

Type Values Removed Values Added
Description The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
Title tarteaucitron.io < 1.9.5 - Contributor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-06-18T06:00:02.019Z

Updated: 2025-06-18T18:35:58.051Z

Reserved: 2025-05-19T12:57:59.033Z

Link: CVE-2025-4955

cve-icon Vulnrichment

Updated: 2025-06-18T18:35:42.111Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-18T06:15:28.397

Modified: 2025-07-02T19:25:30.180

Link: CVE-2025-4955

cve-icon Redhat

No data.