CVE-2010-4277

Jovelstefan Embedded-video - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in lembedded-video.php in the Embedded Video plugin 4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the content parameter to wp-admin/post.php.

Scores

EPSS 0.0015
EPSS Percentile 35.8%

Classification

CWE
CWE-79
Status published

Affected Products (2)

jovelstefan/embedded-video
n/a/n/a

Timeline

Published Dec 22, 2010
Tracked Since Feb 18, 2026