Security Advisory

CVE-2026-84937

N/A
UNKNOWN

Vulnerability Description

The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.
Published Date September 5, 2026
Official Source NIST NVD Advisory