Impact
The vulnerability is DOM‑Based XSS caused by improper sanitization of user‑supplied data generated by the Video.js HLS Player plugin. An attacker can craft inputs that execute arbitrary script in the victim's browser, leading to session hijacking, data theft, or defacement.
Affected Systems
The issue exists in the WordPress plugin Video.js HLS Player version 1.0.2 and earlier. Any site running Bruce's Video.js HLS Player plugin up to and including 1.0.2 is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is below 1%, implying a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be web‑based, with an attacker inserting malicious data via the plugin’s rendering of video URLs or plugin configuration. Successful exploitation would allow the attacker to execute arbitrary scripts in the context of the site visitor.
OpenCVE Enrichment
EUVD