Impact
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to a stored cross‑site scripting flaw caused by insufficient input sanitization and output escaping in plugin settings. Authenticated users with editor or higher permissions can inject arbitrary web scripts that will execute whenever a visitor accesses a page that uses the injected data. This enables attackers to hijack sessions, deface content, or deliver malicious payloads. The weakness corresponds to CWE‑79.
Affected Systems
WordPress installations that use the Video Share VOD – Turnkey Video Site Builder Script plugin, versions up to and including 2.7.11. The issue appears only on multi‑site setups and when the unfiltered_html setting is disabled. All users of the affected versions are potentially at risk if the plugin is used in this configuration.
Risk and Exploitability
The vulnerability receives a CVSS score of 4.4, indicating a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, and the flaw is not listed in the CISA KEV catalog. Exploitability requires authenticated access with editor or higher privileges, making the threat largely confined to sites where such permissions are granted. However, once compromised, the stored malicious script can affect any visitor to the affected pages.
OpenCVE Enrichment