Yotuwp develops a video gallery product whose vulnerability profile centers on server-side input handling and authentication weaknesses, particularly PHP remote file inclusion, cross-site scripting, and improper authentication controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yotuwp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35726CRITICAL Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress. | Aug 23, 2022 | 9.8 | 29 | NO | NO |
CVE-2024-4258CRITICAL The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the sett | Jun 15, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-4551HIGH The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the disp | Jun 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-25477MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yotuwp Video Gallery plugin <= 1.3.12 versions. | Sep 1, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yotuwp.
Media articles that mention a CVE ID that affects a product developed by Yotuwp — matched by CVE ID, not by vendor name.