Junglewise Threat Intelligence

CVE-2026-8877: WordPress Responsive Video Embedder Stored XSS in rem_video shortcode

CVE-2026-8877 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Vendors: Wordpress.

Executive brief

The Responsive Video Embedder plugin for WordPress, which allows site owners to easily embed videos, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts execute automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft. This could damage a site's reputation and compromise the security of its visitors.

Technical details

The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'rem_video' shortcode in versions up to, and including, 0.1. The vulnerability exists within the video_shortcode() function, where user-supplied attributes such as 'id' and 'list' are concatenated directly into an HTML iframe's src attribute without proper sanitization or output escaping. An authenticated attacker with contributor-level permissions or higher can exploit this to inject arbitrary web scripts. These scripts are stored on the server and execute in the context of any user's browser who visits the compromised page.

Affected products

  • WordPress Responsive Video Embedder Up to, and including, 0.1

Timeline

  • 2026-05-27: disclosed: Initial publication of the vulnerability advisory.
  • 2026-05-27: advisory: NVD published the CVE record.

References