Vulnerabilities > Plugin > Yourchannel > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-1865 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in versions up to, and including, 1.2.3.
network
low complexity
plugin
6.5
2023-04-05 CVE-2023-1866 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.
network
low complexity
plugin
4.3
2023-04-05 CVE-2023-1867 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.
network
low complexity
plugin
4.3
2023-04-05 CVE-2023-1868 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3.
network
low complexity
plugin
5.3
2023-04-05 CVE-2023-1869 Cross-site Scripting vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping.
network
low complexity
plugin CWE-79
4.8
2023-04-05 CVE-2023-1870 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.
network
low complexity
plugin
4.3
2023-04-05 CVE-2023-1871 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.
network
low complexity
plugin
4.3
2023-02-06 CVE-2022-4833 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
network
low complexity
plugin
5.4
2023-02-06 CVE-2023-0282 Unspecified vulnerability in Plugin Yourchannel
The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.
network
low complexity
plugin
5.4