Cross-site Scripting Vulnerability in Live Streaming Video Player by SRS
CVE-2025-27327
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 February 2025
What is CVE-2025-27327?
A Cross-site Scripting (XSS) vulnerability exists in the Live Streaming Video Player by SRS Player, enabling attackers to execute scripts in the context of a victim's browser session. This flaw arises from improper handling of user input during web page generation, allowing attackers to inject malicious scripts. As a result, users may be susceptible to data theft, session hijacking, and other malicious activities. The vulnerability impacts all versions of the player up to and including 1.0.18, necessitating immediate attention from administrators to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Live Streaming Video Player β by SRS Player <= 1.0.18
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved