CVE-2025-31057: WordPress Universal Video Player plugin <= 1.4.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player allows Reflected XSS. This issue affects Universal Video Player: from n/a through 1.4.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player elementorwidgetuniversalvideoplayer allows Reflected XSS.This issue affects Universal Video Player: from n/a through <= 1.4.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31057?
CVE-2025-31057 has a medium severity level due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-31057?
To mitigate CVE-2025-31057, upgrade the Universal Video Player to the latest version beyond 1.4.0.
What software is affected by CVE-2025-31057?
CVE-2025-31057 affects LambertGroup Universal Video Player and WordPress Universal Video Player versions up to 1.4.0.
What type of vulnerability is CVE-2025-31057?
CVE-2025-31057 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2025-31057 be exploited remotely?
Yes, CVE-2025-31057 can potentially be exploited remotely if an attacker injects malicious scripts into web pages viewed by users.