CVE-2026-88793: YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server

Published Sep 13, 2026
·
Updated

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator.

Affected Software

1 affected component
WordPress plugin "YouTube Embed">=10.0<=10.3

Event History

Sep 13, 2026
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which installations are affected?

The affected versions are YouTube Embed 10.0 through 10.3 for WordPress. The issue is in an AJAX action named youram_server.

2

Does exploiting this require a WordPress account or special privileges?

No. The vulnerable AJAX action lacks an authorization check, so an unauthenticated attacker can exploit it. The attacker needs a nonce that is printed on every front-end page.

3

Who is at risk from the stored script execution?

Any user who views the affected content can have the injected script execute in their browser session. This includes WordPress administrators, whose sessions may expose higher-impact actions or data.

4

Is user interaction required for impact?

Yes. The injected script executes when a user views the affected content. The attacker can store the payload without authentication, but a victim must load the rendered content for the script to run.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203