CVE-2025-22566: WordPress ULTIMATE VIDEO GALLERY Plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendyourweb ULTIMATE VIDEO GALLERY ultimate-gallery allows Reflected XSS.This issue affects ULTIMATE VIDEO GALLERY: from n/a through <= 1.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ULTIMATE VIDEO GALLERY allows Reflected XSS. This issue affects ULTIMATE VIDEO GALLERY: from n/a through 1.4.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22566?
CVE-2025-22566 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS).
How do I fix CVE-2025-22566?
To fix CVE-2025-22566, update the NotFound ULTIMATE VIDEO GALLERY to the latest version beyond 1.4 to ensure the vulnerability is patched.
What versions are affected by CVE-2025-22566?
CVE-2025-22566 affects NotFound ULTIMATE VIDEO GALLERY versions up to and including 1.4.
What type of vulnerability is CVE-2025-22566?
CVE-2025-22566 is an improper neutralization of input during web page generation that allows for reflected cross-site scripting (XSS).
Who is impacted by CVE-2025-22566?
Users of the NotFound ULTIMATE VIDEO GALLERY and WordPress ULTIMATE VIDEO GALLERY Plugin up to version 1.4 are impacted by CVE-2025-22566.