Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS playerjs allows DOM-Based XSS.This issue affects PlayerJS: from n/a through <= 2.23.
Published: 2025-02-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The PlayerJS plugin contains an improper neutralization of input during page generation that results in a DOM‑based XSS flaw. An attacker who can influence the content that the plugin renders can inject malicious scripts that run in the context of a victim’s browser. This can lead to theft of user‑session data, defacement of the site, or delivery of additional malware, exploiting the input validation weakness identified as CWE‑79.

Affected Systems

WordPress installations that use the PlayerJS plugin, versions up to and including 2.23, are vulnerable. The plugin is distributed under the PlayerJS product and is commonly embedded in media‑rich WordPress themes and sites.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% reflects a low probability of being exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would likely involve a crafted URL or input that triggers the plugin’s DOM parsing routines, suggesting that a remote attacker could trigger the XSS simply by directing a user to a malicious link or injecting data into a page that the plugin processes.

Generated by OpenCVE AI on May 2, 2026 at 09:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the PlayerJS plugin to the latest released version that contains the XSS fix.
  • If an immediate update is not feasible, disable or de‑activate the PlayerJS plugin to eliminate the attack surface until the patch can be applied.
  • Implement a content security policy header that restricts script execution to trusted sources and mitigates XSS risk.

Generated by OpenCVE AI on May 2, 2026 at 09:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4316 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS allows DOM-Based XSS. This issue affects PlayerJS: from n/a through 2.23.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS allows DOM-Based XSS. This issue affects PlayerJS: from n/a through 2.23. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS playerjs allows DOM-Based XSS.This issue affects PlayerJS: from n/a through <= 2.23.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 24 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS allows DOM-Based XSS. This issue affects PlayerJS: from n/a through 2.23.
Title WordPress PlayerJS plugin <= 2.23 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:48.199Z

Reserved: 2025-02-21T16:45:48.523Z

Link: CVE-2025-27330

cve-icon Vulnrichment

Updated: 2025-02-24T16:51:47.715Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:18.660

Modified: 2026-06-17T09:03:24.757

Link: CVE-2025-27330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:15:26Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')