Stored Cross-Site Scripting Vulnerability in Voltax Video Player Plugin by WordPress
CVE-2025-6539
6.4MEDIUM
What is CVE-2025-6539?
The Voltax Video Player plugin for WordPress has a vulnerability that allows authenticated attackers with Contributor-level access or higher to perform Stored Cross-Site Scripting attacks. By exploiting this vulnerability through insufficient input sanitization and output escaping in the āidā parameter, adversaries can inject arbitrary web scripts. The injected scripts will execute whenever a user accesses affected pages, posing significant security risks to users of the plugin.
Affected Version(s)
Voltax Video Player * <= 1.6.5