Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager video-list-manager allows Stored XSS.This issue affects Video List Manager: from n/a through <= 1.7.
Published: 2025-07-04
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Video List Manager plugin suffers from an improper neutralization of input during web page generation. Stored cross–site scripting allows attackers to inject arbitrary JavaScript that is executed in the browsers of users who view the affected pages. This weakness (CWE-79) can lead to phishing, credential theft, or the execution of malicious code within the victim’s environment.

Affected Systems

The affected vendor is thanhtungtnt and the product is the Video List Manager plugin. Any installation of the plugin version 1.7 or earlier is potentially vulnerable. In the absence of more granular version data, all releases up to and including 1.7 are considered affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is below 1 %, suggesting that exploit attempts are unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through the plugin’s input fields or list editing interface, where an attacker can store malicious payloads that are later rendered on pages accessed by other users. The attack requires the ability to create or modify video list entries; if the site allows anonymous posting, the risk would be higher, but if only administrators can edit, the threat is still significant due to the stored nature of the payload.

Generated by OpenCVE AI on April 30, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Video List Manager plugin to the latest version, which removes the stored XSS flaw
  • If upgrading is not yet possible, temporarily disable or delete the plugin to eliminate the attack surface
  • After the plugin is upgraded or the entries are rewritten, review all existing video list content to ensure no malicious scripts remain

Generated by OpenCVE AI on April 30, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19995 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager allows Stored XSS. This issue affects Video List Manager: from n/a through 1.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager allows Stored XSS. This issue affects Video List Manager: from n/a through 1.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager video-list-manager allows Stored XSS.This issue affects Video List Manager: from n/a through <= 1.7.
Title WordPress Video List Manager <= 1.7 - Cross Site Scripting (XSS) Vulnerability WordPress Video List Manager plugin <= 1.7 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 07 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager allows Stored XSS. This issue affects Video List Manager: from n/a through 1.7.
Title WordPress Video List Manager <= 1.7 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:18.635Z

Reserved: 2025-06-19T10:03:09.016Z

Link: CVE-2025-52776

cve-icon Vulnrichment

Updated: 2025-07-07T16:25:53.612Z

cve-icon NVD

Status : Deferred

Published: 2025-07-04T12:15:33.370

Modified: 2026-04-23T15:32:09.150

Link: CVE-2025-52776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:00:16Z

Weaknesses