The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Amauri
Amauri tarteaucitron.io |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:amauri:tarteaucitron.io:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Amauri
Amauri tarteaucitron.io |
Wed, 18 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 18 Jun 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks. | |
Title | tarteaucitron.io < 1.9.5 - Contributor+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-06-18T06:00:02.019Z
Updated: 2025-06-18T18:35:58.051Z
Reserved: 2025-05-19T12:57:59.033Z
Link: CVE-2025-4955

Updated: 2025-06-18T18:35:42.111Z

Status : Analyzed
Published: 2025-06-18T06:15:28.397
Modified: 2025-07-02T19:25:30.180
Link: CVE-2025-4955

No data.