Cross-site Scripting Vulnerability in LambertGroup Radio Player Shoutcast & Icecast
CVE-2025-53205
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-53205?
The LambertGroup Radio Player Shoutcast & Icecast is vulnerable to a Cross-site Scripting (XSS) issue due to improper input neutralization during web page generation. This flaw allows attackers to inject malicious scripts into the web pages served by the application, potentially compromising user data and session cookies. Affected versions range from n/a through 4.4.7. It is critical for users of this application to apply security updates and validate user inputs to mitigate the risk of exploitation.
Affected Version(s)
Radio Player Shoutcast & Icecast <= 4.4.7
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)