Impact
The flaw arises from the WP-Player plugin failing to properly neutralize user-supplied input before embedding it into web pages. An attacker who can add or edit content managed by WP-Player can store a malicious script that is later served to any visitor of the site, resulting in client-side code execution. This does not compromise the server itself, but it can lead to phishing, cookie theft or other client-side attacks within the context of the affected site.
Affected Systems
The vulnerability is present in all releases of the WP-Player plugin whose version is 2.6.1 or earlier. The vendor is M.J, offering the WP-Player add-on for WordPress.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1 % suggests that exploitation is unlikely at the time of analysis. The CVE is not listed in the CISA KEV catalogue. Because the issue is a stored XSS, the most likely attack vector is through normal web interactions; any authenticated or unauthenticated user who can create or modify plugin content can insert the malicious payload, which is then rendered for all visitors who load the affected page.
OpenCVE Enrichment
EUVD