CVE-2025-31058: WordPress Revolution Video Player plugin <= 2.9.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Revolution Video Player allows Reflected XSS. This issue affects Revolution Video Player: from n/a through 2.9.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Revolution Video Player revolutionvideoplayer allows Reflected XSS.This issue affects Revolution Video Player: from n/a through <= 2.9.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31058?
CVE-2025-31058 is classified as a high severity vulnerability due to its potential for exploitation via reflected XSS.
How do I fix CVE-2025-31058?
To fix CVE-2025-31058, update the Revolution Video Player to version 2.9.3 or later.
What systems are affected by CVE-2025-31058?
CVE-2025-31058 affects LambertGroup Revolution Video Player and WordPress Revolution Video Player versions up to and including 2.9.2.
What type of vulnerability is CVE-2025-31058?
CVE-2025-31058 is a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2025-31058 be exploited remotely?
Yes, CVE-2025-31058 can be exploited remotely, allowing attackers to inject malicious scripts into webpages.