Impact
Improper neutralization of user supplied input in the Sandeep Verma HTML5 Video Player with Playlist plugin leads to a reflected Cross‑Site Scripting flaw. This weakness (CWE‑79) allows an attacker to inject and execute arbitrary client‑side scripts when a victim visits a crafted URL. The impact can range from session hijacking and defacement to credential theft, all of which compromise the confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The vulnerability is present in the HTML5 Video Player with Playlist plugin for WordPress as distributed by Sandeep Verma. Versions from the initial release up to and including 2.50 are affected. Any WordPress installation that has this plugin enabled is exposed.
Risk and Exploitability
The CVSS score of 7.1 categorises the issue as high severity, and the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability as a remote, unauthenticated attacker by crafting a malicious URL that the plugin reflects back into the response. This requires only that the victim visit the malicious link, making the threat vector widely accessible from the Internet.
OpenCVE Enrichment
EUVD