Description
Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Cross Site Request Forgery.This issue affects Elite Video Player: from n/a through <= 10.0.5.
Published: 2025-06-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw in the Elite Video Player plugin. The likely attack vector is a forged request made via a victim who is tricked into visiting a malicious site and inadvertently submitting a request to the target WordPress instance. An attacker who tricks a legitimate user into visiting a crafted page could cause the victim to unknowingly submit requests that alter the plugin’s configuration or perform other state‑changing actions. The impact is limited to authorization abuse and data modification rather than privilege escalation or denial of service; the CVSS score reflects a moderate risk.

Affected Systems

The flaw affects the CreativeMedia Elite Video Player plugin in all releases from the earliest available through version 10.0.5. Users running any of these versions on WordPress sites are potentially vulnerable.

Risk and Exploitability

With a CVSS score of 5.4 and an EPSS probability of less than 1%, the likelihood of exploitation is low, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation typically requires a phishing or social‑engineering step to lure a privileged user to a malicious site that submits a forged request to the target WordPress instance. Once the request is accepted, the attacker can modify plugin settings or perform other actions permitted by the victim’s privileges.

Generated by OpenCVE AI on May 1, 2026 at 07:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Elite Video Player plugin to version 10.0.6 or later to eliminate the CSRF vulnerability.
  • Configure the plugin or WordPress to limit the capabilities of non‑administrator roles so that only trusted accounts can perform state‑changing actions.
  • Implement additional CSRF protection mechanisms across the site, such as a site‑wide security plugin that validates anti‑CSRF tokens on state‑changing requests.

Generated by OpenCVE AI on May 1, 2026 at 07:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17231 Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player allows Cross Site Request Forgery. This issue affects Elite Video Player: from n/a through 10.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player allows Cross Site Request Forgery. This issue affects Elite Video Player: from n/a through 10.0.5. Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Cross Site Request Forgery.This issue affects Elite Video Player: from n/a through <= 10.0.5.
Title WordPress Elite Video Player <= 10.0.5 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Elite Video Player plugin <= 10.0.5 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Fri, 06 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player allows Cross Site Request Forgery. This issue affects Elite Video Player: from n/a through 10.0.5.
Title WordPress Elite Video Player <= 10.0.5 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:03.355Z

Reserved: 2025-03-26T09:22:41.972Z

Link: CVE-2025-30986

cve-icon Vulnrichment

Updated: 2025-06-06T15:13:10.789Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:38.060

Modified: 2026-04-23T15:27:27.637

Link: CVE-2025-30986

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:00:13Z

Weaknesses