CVE-2024-6256: Feeds for YouTube (YouTube video, channel, and gallery plugin) <= 2.2.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Feeds for YouTube (YouTube video, channel, and gallery plugin)to a version that resolves this vulnerability.Fixed in 2.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6256?
CVE-2024-6256 is classified as a medium severity vulnerability due to its potential for Stored Cross-Site Scripting.
How do I fix CVE-2024-6256?
To fix CVE-2024-6256, update the Feeds for YouTube plugin to version 2.2.2 or later.
Who is affected by CVE-2024-6256?
CVE-2024-6256 affects all versions of the Feeds for YouTube plugin up to and including version 2.2.1.
What type of vulnerability is CVE-2024-6256?
CVE-2024-6256 is a Stored Cross-Site Scripting vulnerability related to insufficient input sanitization.
What can attackers do with CVE-2024-6256?
Attackers exploiting CVE-2024-6256 can execute arbitrary JavaScript in the context of the user's session.