Stored Cross-Site Scripting in Target Video Easy Publish Plugin for WordPress
CVE-2025-5237
6.4MEDIUM
What is CVE-2025-5237?
The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter, affecting versions up to and including 3.8.5. This vulnerability arises from inadequate input sanitization and output escaping. Authenticated attackers with Contributor-level access and above can exploit this flaw to inject arbitrary web scripts. Once injected, these scripts execute whenever any user accesses the affected page, potentially compromising user data and site integrity.
Affected Version(s)
Target Video Easy Publish * <= 3.8.5