{"id":"CVE-2026-84937","title":"The Video Player for YouTube  WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks…","summary":"The Video Player for YouTube  WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-89"],"published":"2026-09-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:15:18.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84937","references":[{"url":"https://wpscan.com/vulnerability/5f81c233-8544-4a7b-a1c6-e447dc889a8d/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00391,"epssPercentile":0.30417,"ingestedAt":"2026-09-06T11:54:30.476Z","slug":"CVE-2026-84937","body":"## Overview\n\nThe Video Player for YouTube  WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}