CVE-2017-6817 describes an authenticated Cross-Site Scripting (XSS) vulnerability in WordPress versions prior to 4.7.3, specifically within the YouTube URL Embed functionality in wp-includes/embed.php. This medium-severity flaw (CVSS 5.4) allows a logged-in attacker to inject malicious scripts, potentially leading to information disclosure and limited data alteration, requiring user interaction. While not actively exploited in the wild (no KEV entry), its presence in WordPress, a widely used platform, warrants attention, and it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.7.2CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.