Medium 6.4
2026-01-28< 3.8.9
Target Video Easy Publish <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter
Minimum safe version
3.8.9
Update to 3.8.9 or later to address 4 fixable vulnerabilities
Target Video Easy Publish <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter
Target Video Easy Publish <= 3.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter
WordPress Target Video Easy Publish plugin <= 3.8.9 - Arbitrary Code Execution vulnerability
CVE-2024-13561
WordPress Target Video Easy Publish Plugin <= 3.8.3 is vulnerable to Cross Site Scripting (XSS)