The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' shortcode. This is due to insufficient input sanitization and output escaping on attachment titles referenced by the shortcode's image field: EMD_MB_Helper::image_info() returns the attachment's raw post_title, and EMD_MB_Helper::shortcode() interpolates it into title="%s" HTML attributes via sprintf() without esc_attr(). This makes it possible for authenticated attackers, with author-level access and above (upload_files capability required to create the attachment, edit_posts/publish_posts to embed the shortcode), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 1,397 live websites that are affected by CVE-2026-15790.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,397 live websites (100% of Youtube Showcase install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 36 versions ( 100% of all versions) |
| 511 websites | |
| 118 websites | |
| 86 websites | |
| 71 websites | |
| 45 websites | |
| 44 websites | |
| 40 websites | |
| 33 websites | |
| 31 websites | |
| 30 websites |
| .com | 638 websites |
| .org | 122 websites |
| .it | 58 websites |
| .de | 44 websites |
| .net | 42 websites |
| .nl | 36 websites |
| .ru | 27 websites |
| .pl | 21 websites |
| .fr | 20 websites |
| .co.uk | 18 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.cz | **,*** | ||
| *************.com | **,*** | ||
| *************.**********.com | ***,*** | ||
| *************.bb | ***,*** | ||
| ***************************.com | ***,*** | ||
| ***.***.nz | ***,*** | ||
| *********************.com | ***,*** | ||
| **********.com | ***,*** | ||
| ***************.***.uk | ***,*** | ||
| *****.com | ***,*** |
FAQ