BlackKite: Home
Menu

PUBLISHED DATE: May 21, 2025CVE-2025-4217:
Cross-Site Scripting Vulnerability

CVSS:
6.4
EPSS:
3.20%
Exploitability:
3.1
In KEV:
No
Description

The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_youtube' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2025-4217, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2025-4217 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?