Impact
The vulnerability is an improper neutralization of input during web page generation, leading to reflected cross‑site scripting in the Universal Video Player plugin for WordPress. An attacker can insert malicious JavaScript into a URL that, when accessed by a user, will be reflected back into the webpage, allowing script execution in the user's browser. This can result in theft of session cookies, defacement of the site, or execution of arbitrary client‑side code.
Affected Systems
Affected products include LambertGroup’s Universal Video Player plugin for WordPress, versions released from the initial version through 3.8.4. Any installation running 3.8.4 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, while an EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The attack vector is likely a reflected request; an attacker can craft a malicious URL and persuade a victim to click it, or potentially embed the payload in a link sent via email or message. Since no authentication is required, any authenticated or unauthenticated user who views the affected page is at risk.
OpenCVE Enrichment