CVE-2025-31426: WordPress Sticky Radio Player plugin <= 3.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Sticky Radio Player allows Reflected XSS. This issue affects Sticky Radio Player: from n/a through 3.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutcaststicky allows Reflected XSS.This issue affects Sticky Radio Player: from n/a through <= 3.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31426?
CVE-2025-31426 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-31426?
To fix CVE-2025-31426, update the Sticky Radio Player to version 3.5 or later, which addresses the input validation issue.
What software is affected by CVE-2025-31426?
CVE-2025-31426 affects LambertGroup Sticky Radio Player versions up to and including 3.4 and the WordPress Sticky Radio Player plugin up to and including 3.4.
What kind of attacks can CVE-2025-31426 facilitate?
CVE-2025-31426 can facilitate reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
Where can I find more information about CVE-2025-31426?
More information about CVE-2025-31426 can be found in security databases and vulnerability disclosures, but specific URLs are not provided here.