Stored Cross-Site Scripting Vulnerability in Presto Player Plugin for WordPress
CVE-2026-9125
6.4MEDIUM
What is CVE-2026-9125?
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting. This issue arises from inadequate input sanitization and output escaping in the handling of the 'link_url' parameter within the [presto_player_overlay] shortcode. Authenticated users with contributor-level access and higher can exploit this vulnerability to inject arbitrary JavaScript code into web pages. When users access these compromised pages, the injected scripts are executed, potentially leading to unauthorized data access or session hijacking.
Affected Version(s)
Presto Player 0 <= 4.2.0