VYPR

Youtube Video Player

by WordPress

CVEs (2)

  • CVE-2025-2537MedJul 3, 2025
    risk 0.42cvss 6.4epss 0.00

    Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScript library (version 3.1) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

  • CVE-2021-24414MedOct 25, 2021
    risk 0.35cvss 5.4epss 0.01

    The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious…