CVE-2025-4955 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could all…
Medium CVSS: 4.7

CVE-2025-4955

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
Vendor
Amauri
Product
Tarteaucitron.io
CWE
CWE-79
Yayın Tarihi
2025-06-18 06:15:28
Güncelleme
2025-07-02 19:25:30
Source Identifier
contact@wpscan.com
KEV Date Added
-

Kategoriler

Referanslar