Cross-site Scripting Vulnerability in LambertGroup Video Player Plugin
CVE-2025-48159
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-48159?
The LambertGroup Youtube Vimeo Video Player and Slider WP Plugin contains a vulnerability that allows attackers to exploit reflected cross-site scripting (XSS) attacks. This flaw enables the injection of malicious scripts through improperly processed user inputs during web page generation. As a result, this vulnerability can lead to unauthorized actions on behalf of users, potentially compromising sensitive data and site integrity. It is crucial for users of this plugin to apply necessary security measures promptly to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Youtube Vimeo Video Player and Slider WP Plugin <= 3.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved