CVE-2023-0446
Published on: Not Yet Published
Last Modified on: 01/23/2023 05:17:00 PM UTC
Certain versions of My YouTube Channel from Urkekg contain the following vulnerability:
The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 3.0.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- CVE-2023-0446 has been assigned by
[email protected] to track the vulnerability
- Affected Vendor/Software:
urkekg - My YouTube Channel version = *
CVE References
Description | Tags ⓘ | Link |
---|---|---|
403 Forbidden | plugins.trac.wordpress.org text/html Inactive LinkNot Archived |
![]() |
My YouTube Channel <= 3.0.12.1 - Authenticated (Administrator+) Stored Cross-Site Scripting | www.wordfence.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Software
Vendor | Product | Version |
---|---|---|
Urkekg | My_YouTube_Channel | = * |
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-0446 : The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its se… twitter.com/i/web/status/1… | 2023-01-23 17:07:23 |