CVE-2025-27005: WordPress HTML5 Video Player plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Video Player lbg-vp2-html5-bottom allows Reflected XSS.This issue affects HTML5 Video Player: from n/a through <= 5.3.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27005?
The severity of CVE-2025-27005 is considered high due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-27005?
To fix CVE-2025-27005, update the LambertGroup HTML5 Video Player plugin to version 5.3.6 or higher.
What versions are affected by CVE-2025-27005?
CVE-2025-27005 affects versions of the LambertGroup HTML5 Video Player plugin up to and including 5.3.5.
What are the risks if CVE-2025-27005 is exploited?
If exploited, CVE-2025-27005 can allow an attacker to execute malicious scripts in the context of an affected user's browser.
Is there a known exploit for CVE-2025-27005?
Yes, there are known exploits for CVE-2025-27005 that demonstrate how the reflected XSS vulnerability can be leveraged.