Junglewise Threat Intelligence

CVE-2026-12923: emarket-design Youtube Showcase arbitrary function call in emd_delete_file

CVE-2026-12923 · Severity: high · CVSS 7.5 · Published 2026-07-01

Executive brief

The Youtube Showcase plugin for WordPress, used to display video galleries and playlists, contains a security flaw that allows logged-in users with basic permissions to execute unauthorized commands. By exploiting this vulnerability, an attacker could gain access to sensitive system information or potentially take further control of the website. This issue stems from a lack of proper security checks when the plugin handles file-related requests.

Technical details

The vulnerability exists in the emd_delete_file() AJAX handler within includes/common-functions.php of the Youtube Showcase plugin. The 'path' parameter is passed through sanitize_text_field(), has the '_PLUGIN_DIR' substring removed, and is then dynamically executed as a PHP function name without arguments. The handler lacks a current_user_can() authorization check and relies solely on a nonce that is exposed on any front-end page containing a file field shortcode. Authenticated attackers with Subscriber-level access or higher can exploit this to invoke arbitrary zero-argument PHP functions, leading to sensitive information disclosure (e.g., via phpinfo) or further system compromise. A patch appears to be available in the plugin's changeset 3588198.

Affected products

  • emarket-design Youtube Showcase (Video Gallery – YouTube Gallery, Playlist & Video Grid) up to and including 4.0.3

Timeline

  • 2026-07-01: advisory: NVD publication date
  • 2026-07-01: disclosed: Wordfence advisory published

References