MEDIUM
WP YouTube Lyte
CVE published 2026-09-27
CVE-2026-96895
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block. This could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks. The vulnerability impacts WordPress installations using the WP YouTube Lyte plugin, particularly those with users having contr [truncated]