Impact
The vulnerability is an improper neutralization of input during web page generation that allows an attacker to inject and persist malicious JavaScript in the Elite Video Player plugin. Stored XSS enables the execution of attacker‑controlled scripts in the browser context of any user who views the compromised page, potentially compromising user credentials, performing account hijacking, or redacting site content. The weakness corresponds to CWE‑79.
Affected Systems
The affected product is Elite Video Player, version 10.0.5 and earlier, developed by CreativeMedia. Users running any of these versions on WordPress sites are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score of less than 1% suggests the chance of exploitation in the wild is very low, and the issue is not currently listed in CISA’s KEV catalog. Unless the plugin is updated or mitigated, a threat actor can craft a malicious URL or embed the attack within a media object that, when viewed, executes the injected script.
OpenCVE Enrichment
EUVD