CVE-2024-3937: Playlist for Youtube <= 1.32 - Editor+ Stored XSS
The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3937?
CVE-2024-3937 has a high severity rating due to the potential for stored cross-site scripting attacks by high privilege users.
How do I fix CVE-2024-3937?
To fix CVE-2024-3937, update the Playlist for Youtube WordPress plugin to the latest version beyond 1.32.
Who is affected by CVE-2024-3937?
CVE-2024-3937 affects users of the Playlist for Youtube WordPress plugin versions up to 1.32.
What type of vulnerability is CVE-2024-3937?
CVE-2024-3937 is a stored cross-site scripting vulnerability allowing unauthorized script execution.
Can CVE-2024-3937 be exploited on all WordPress sites?
CVE-2024-3937 can be exploited on WordPress sites using the affected plugin with high privilege users like admins.