Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC YouTube Downloader allows Stored XSS.This issue affects MDC YouTube Downloader: from n/a through 3.0.0.
References
Configurations
Configuration 1 (hide)
|
History
30 Sep 2025, 21:33
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mdc Youtube Downloader Project mdc Youtube Downloader
Mdc Youtube Downloader Project |
|
CPE | cpe:2.3:a:mdc_youtube_downloader_project:mdc_youtube_downloader:*:*:*:*:*:wordpress:*:* | |
References | () https://patchstack.com/database/wordpress/plugin/mdc-youtube-downloader/vulnerability/wordpress-mdc-youtube-downloader-plugin-3-0-0-csrf-to-stored-xss-vulnerability?_s_id=cve - Third Party Advisory | |
Summary |
|
16 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-16 20:15
Updated : 2025-09-30 21:33
NVD link : CVE-2025-23639
Mitre link : CVE-2025-23639
CVE.ORG link : CVE-2025-23639
JSON object : View
Products Affected
mdc_youtube_downloader_project
- mdc_youtube_downloader
CWE
CWE-352
Cross-Site Request Forgery (CSRF)