cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forstreamweasels-youtube-integration streamweasels-youtube-integration

Direction: ascending
Jun 07, 2024

StreamWeasels YouTube Integration # ed820e821660528f211ccfe5f0e1a6d66ca180e5

Date
Jul 18, 2023
Research Description
StreamWeasels YouTube Integration [streamweasels-youtube-integration] < 1.1.4 WordPress StreamWeasels YouTube Integration Plugin < 1.1.4 is vulnerable to Cross Site Scripting (XSS) Update the plugin to the latest version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress StreamWeasels YouTube Integration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.1.4.
Affected versions
max 1.1.4.
Status
vulnerable
Oct 30, 2024

StreamWeasels YouTube Integration # CVE-2024-10185

CVE, Research URL

CVE-2024-10185

Date
Oct 29, 2024
Research Description
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.3.3.
Status
vulnerable
Nov 29, 2024

StreamWeasels YouTube Integration # CVE-2024-11788

CVE, Research URL

CVE-2024-11788

Date
Nov 28, 2024
Research Description
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.3.7.
Status
vulnerable
Aug 01, 2025

StreamWeasels YouTube Integration # CVE-2025-7811

CVE, Research URL

CVE-2025-7811

Date
Jul 29, 2025
Research Description
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.4.1.
Status
vulnerable