Stored Cross-Site Scripting in Target Video Easy Publish Plugin for WordPress
CVE-2025-5237

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 June 2025

What is CVE-2025-5237?

The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter, affecting versions up to and including 3.8.5. This vulnerability arises from inadequate input sanitization and output escaping. Authenticated attackers with Contributor-level access and above can exploit this flaw to inject arbitrary web scripts. Once injected, these scripts execute whenever any user accesses the affected page, potentially compromising user data and site integrity.

Affected Version(s)

Target Video Easy Publish * <= 3.8.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis
.