Description
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
Remediation
References
Related Vulnerabilities
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2016-9707)
WordPress Plugin StoryChief Cross-Site Scripting (1.0.30)
Mailman Other Vulnerability (CVE-2004-1143)
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.15)
WordPress Plugin iCopyright Toolbar 'icopyright_xml.php' SQL Injection (1.1.4)