Impact
The PlayerJS plugin contains an improper neutralization of input during page generation that results in a DOM‑based XSS flaw. An attacker who can influence the content that the plugin renders can inject malicious scripts that run in the context of a victim’s browser. This can lead to theft of user‑session data, defacement of the site, or delivery of additional malware, exploiting the input validation weakness identified as CWE‑79.
Affected Systems
WordPress installations that use the PlayerJS plugin, versions up to and including 2.23, are vulnerable. The plugin is distributed under the PlayerJS product and is commonly embedded in media‑rich WordPress themes and sites.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% reflects a low probability of being exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would likely involve a crafted URL or input that triggers the plugin’s DOM parsing routines, suggesting that a remote attacker could trigger the XSS simply by directing a user to a malicious link or injecting data into a page that the plugin processes.
OpenCVE Enrichment
EUVD