Cross-site Scripting Vulnerability in WP Video Posts by cmstactics
CVE-2025-27308
What is CVE-2025-27308?
A Cross-site Scripting (XSS) vulnerability exists in the WP Video Posts plugin developed by cmstactics, allowing attackers to execute malicious scripts in the context of a user's web browser. This vulnerability occurs due to improper neutralization of user input during web page generation, specifically leading to reflected XSS attacks. Attackers can exploit this weakness to deliver harmful scripts, compromising user data and potentially gaining unauthorized access to website functionalities. The affected versions range from n/a to 3.5.1, emphasizing the need for users to update to a secure version to prevent possible exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Video Posts <= 3.5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved