Cross-site Scripting Vulnerability in LambertGroup Video Player Plugin
CVE-2025-48159

7.1HIGH

What is CVE-2025-48159?

The LambertGroup Youtube Vimeo Video Player and Slider WP Plugin contains a vulnerability that allows attackers to exploit reflected cross-site scripting (XSS) attacks. This flaw enables the injection of malicious scripts through improperly processed user inputs during web page generation. As a result, this vulnerability can lead to unauthorized actions on behalf of users, potentially compromising sensitive data and site integrity. It is crucial for users of this plugin to apply necessary security measures promptly to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Youtube Vimeo Video Player and Slider WP Plugin <= 3.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 (Patchstack Alliance)
.