Cross-site Scripting Vulnerability in Live Streaming Video Player by SRS
CVE-2025-27327
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 February 2025
What is CVE-2025-27327?
A Cross-site Scripting (XSS) vulnerability exists in the Live Streaming Video Player by SRS Player, enabling attackers to execute scripts in the context of a victim's browser session. This flaw arises from improper handling of user input during web page generation, allowing attackers to inject malicious scripts. As a result, users may be susceptible to data theft, session hijacking, and other malicious activities. The vulnerability impacts all versions of the player up to and including 1.0.18, necessitating immediate attention from administrators to prevent exploitation.
Affected Version(s)
Live Streaming Video Player – by SRS Player <= 1.0.18