Impact
Unauthenticated Cross Site Scripting (XSS) has been discovered in CP Media Player plugin versions 1.3.0 and earlier. The vulnerability allows an attacker to inject malicious scripts into web pages rendered by the plugin. Based on the nature of XSS, it is inferred that an attacker could potentially achieve session hijacking, credential theft, defacement, or other client‑side attacks. The flaw is caused by improper input validation and lack of output encoding, a classic example of CWE‑79.
Affected Systems
The affected product is the CP Media Player WordPress plugin developed by Codepeople. All WordPress sites using this plugin version 1.3.0 or older are vulnerable. No specific WordPress core or theme versions are required; the flaw resides solely within the plugin code.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high risk. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that because the flaw is unauthenticated and client‑side, any user who visits an affected page can trigger the exploit, making it highly actionable by attackers who can host malicious content or send crafted links. Accordingly, no further exploitation probability can be determined.
OpenCVE Enrichment