Impact
The Universal Video Player plugin contains an improper neutralization of input during web page generation (a CWE‑79 XSS weakness) that allows attackers to inject arbitrary JavaScript via reflected XSS. When a specially crafted request is processed, the plugin outputs the attacker‑controlled data directly into the page without adequate escaping, enabling execution of malicious scripts in the victim’s browser. This can lead to session hijacking, credential theft, or defacement of the site.
Affected Systems
All installations of LambertGroup’s Universal Video Player plugin version 3.8.4 and earlier are affected. The vendor acknowledges vulnerability impact up to and including the 3.8.4 release.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of <1% shows a very low probability of exploitation as of the current data. The vulnerability is accessible without authentication. Based on the description, it is inferred that an attacker could trigger the issue by submitting input that is reflected in the plugin’s output, such as via a crafted URL or form. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been confirmed yet.
OpenCVE Enrichment