
CVE-2026-1608 The Video Onclick plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `youtube` shortcode in all versions up to, and including, 0.4.7 due… https://www.cve.org/CVERecord?id=CVE-2026-1608
Post summary
The Video Onclick plugin for WordPress is vulnerable to stored XSS through its youtube shortcode in all versions up to 0.4.7, as documented by CVE‑2026‑1608.
