Impact
A reflected cross‑site scripting flaw exists in the Revolution Video Player plugin. Improper neutralization of input during web page generation allows an attacker to inject and execute arbitrary JavaScript in the victim’s browser when a crafted URL is accessed. This flaw is identified as CWE‑79 and can be exploited by any visitor processing the URL without requiring authentication.
Affected Systems
The vulnerability affects the WordPress Revolution Video Player plugin bundled by LambertGroup, from any earlier version up to and including 2.9.2. These versions are commonly deployed in WordPress installations that host video content.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via a web browser when a user follows a maliciously crafted link or visits a page containing the vulnerable query parameters. No prerequisite authentication is required; the flaw is exploitable by any visitor who processes the URL.
OpenCVE Enrichment
EUVD