Cross-site Scripting Vulnerability in WP Video Posts by cmstactics
CVE-2025-27308
7.1HIGH
What is CVE-2025-27308?
A Cross-site Scripting (XSS) vulnerability exists in the WP Video Posts plugin developed by cmstactics, allowing attackers to execute malicious scripts in the context of a user's web browser. This vulnerability occurs due to improper neutralization of user input during web page generation, specifically leading to reflected XSS attacks. Attackers can exploit this weakness to deliver harmful scripts, compromising user data and potentially gaining unauthorized access to website functionalities. The affected versions range from n/a to 3.5.1, emphasizing the need for users to update to a secure version to prevent possible exploitation.
Affected Version(s)
WP Video Posts <= 3.5.1