VYPR

Youtube Showcase

by WordPress

Source repositories

CVEs (4)

  • CVE-2025-54731HigAug 28, 2025
    risk 0.53cvss 8.1epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showcase allows Object Injection.This issue affects YouTube Showcase: from n/a through <= 3.5.1.

  • CVE-2026-15790MedAug 16, 2026
    risk 0.42cvss 6.4epss

    The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' shortcode. This is due to insufficient input sanitization and output escaping on attachment titles referenced by the shortcode's…

  • CVE-2025-15636MedApr 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design YouTube Showcase youtube-showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a through <= 3.5.1.

  • CVE-2026-12923HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied…