PatchSiren

WP YouTube Lyte CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WP YouTube Lyte CVE published 2026-09-27

CVE-2026-96895

The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block. This could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks. The vulnerability impacts WordPress installations using the WP YouTube Lyte plugin, particularly those with users having contr [truncated]