Description
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
Remediation
References
Related Vulnerabilities
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-41799)
WordPress Plugin WP Frontend Profile Security Bypass (1.2.1)
WordPress Plugin Mail Masta Local File Inclusion (1.0)
WordPress Plugin Resize Image After Upload Cross-Site Request Forgery (1.8.5)
WordPress Plugin Redux Framework Cross-Site Request Forgery (4.1.20)