Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.
Published: 2025-08-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability results from improper neutralization of user supplied input when generating a WordPress page, allowing attackers to embed malicious script code that is reflected back to the victim’s browser. The weakness falls under cross‑site scripting and can be exploited to steal session cookies, hijack user accounts, display counterfeit content, or redirect users to phishing sites. The impact is degradation of user confidentiality and integrity, potentially leading to credential compromise or defacement of the site. The flaw is classified as CWE‑79.

Affected Systems

All sites running LambertGroup Universal Video Player - Addon for WPBakery Page Builder on WordPress that are at or below version 3.2.1 are vulnerable. The plugin integrates with the WPBakery Page Builder and is activated via the WordPress theme or plugin interface.

Risk and Exploitability

The CVSS score of 7.1 signifies a high severity risk, while the EPSS score of less than 1% indicates that, at the time of analysis, the probability of exploitation in the wild is low. The flaw is not listed in the CISA KEV catalog. Attackers can exploit this reflected XSS by crafting a malicious link or form input that the plugin improperly sanitizes, leading the victim’s browser to execute injected script when the malicious data is rendered. Successful exploitation requires only that a user view the manipulated page; no administrative privileges are needed.

Generated by OpenCVE AI on April 30, 2026 at 08:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Universal Video Player – Addon for WPBakery Page Builder to the latest available version, which removes the vulnerable input handler.
  • Configure a Web Application Firewall or use a security plugin to block or sanitize script tags that may be injected via the plugin’s parameters.
  • If an upgrade is not immediately possible, disable or remove the plugin from the site and replace it with a trusted alternative that correctly validates or escapes user input.

Generated by OpenCVE AI on April 30, 2026 at 08:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28530 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder allows Reflected XSS. This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through 3.2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder allows Reflected XSS. This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through 3.2.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 20 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder allows Reflected XSS. This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through 3.2.1.
Title WordPress Universal Video Player - Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:26.238Z

Reserved: 2025-07-03T14:50:56.329Z

Link: CVE-2025-53559

cve-icon Vulnrichment

Updated: 2025-08-20T14:15:55.607Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:41.990

Modified: 2026-04-23T15:32:35.490

Link: CVE-2025-53559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')