Junglewise Threat Intelligence

CVE-2026-8847: Dideo WordPress plugin stored XSS in dideo shortcode

CVE-2026-8847 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Executive brief

The Dideo plugin for WordPress, which is used to embed videos, contains a security flaw that allows users with contributor-level access or higher to plant malicious scripts on the website. When other users or administrators visit the affected pages, these scripts can execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

The Dideo plugin for WordPress (v1.0) is vulnerable to Stored Cross-Site Scripting (XSS) due to improper handling of the 'id' attribute within the 'dideo' shortcode. The 'id' value is interpolated directly into an HTML iframe 'src' attribute in the dideo() shortcode handler without sufficient sanitization or output escaping. An authenticated attacker with contributor-level permissions or higher can exploit this to inject arbitrary web scripts into pages. These scripts will execute in the context of any user's browser who visits the compromised page. The vulnerability is tracked as CWE-79.

Affected products

  • Dideo Dideo 1.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References