CVE-2025-27298: WordPress WP Video Posts plugin <= 3.5.1 - CSRF to Remote Code Execution (RCE) vulnerability
Published Feb 24, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection.This issue affects WP Video Posts: from n/a through <= 3.5.1.
Affected Software
1 affected component
Cmstactics WP Video Posts<=3.5.1
Event History
Feb 24, 2025
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-27298?
CVE-2025-27298 is classified as a critical vulnerability due to its potential for OS Command Injection through Cross-Site Request Forgery.
2
How do I fix CVE-2025-27298?
To fix CVE-2025-27298, update the WP Video Posts plugin to the latest version beyond 3.5.1.
3
What software is affected by CVE-2025-27298?
CVE-2025-27298 affects the WP Video Posts plugin for WordPress versions up to and including 3.5.1.
4
What type of vulnerability is CVE-2025-27298?
CVE-2025-27298 is a Cross-Site Request Forgery (CSRF) vulnerability that allows for OS Command Injection.
5
What can attackers do with CVE-2025-27298?
Attackers exploiting CVE-2025-27298 can execute arbitrary OS commands on the server hosting the vulnerable WP Video Posts plugin.