Cross-site Scripting Vulnerability in WP Video Posts by cmstactics
CVE-2025-27308

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 April 2025

What is CVE-2025-27308?

A Cross-site Scripting (XSS) vulnerability exists in the WP Video Posts plugin developed by cmstactics, allowing attackers to execute malicious scripts in the context of a user's web browser. This vulnerability occurs due to improper neutralization of user input during web page generation, specifically leading to reflected XSS attacks. Attackers can exploit this weakness to deliver harmful scripts, compromising user data and potentially gaining unauthorized access to website functionalities. The affected versions range from n/a to 3.5.1, emphasizing the need for users to update to a secure version to prevent possible exploitation.

Affected Version(s)

WP Video Posts <= 3.5.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

johska (Patchstack Alliance)
.