Vulnerability Description
The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-84937?
CVE-2026-84937 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and a...
How severe is CVE-2026-84937?
CVE-2026-84937 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84937?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.