CVE-2025-31917: WordPress Universal Video Player plugin <= 3.8.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player allows Reflected XSS. This issue affects Universal Video Player: from n/a through 3.8.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player universalvideoplayer allows Reflected XSS.This issue affects Universal Video Player: from n/a through <= 3.8.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31917?
CVE-2025-31917 is classified as a Reflected Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-31917?
To fix CVE-2025-31917, update the Universal Video Player plugin to a version beyond 3.8.3.
Which versions of Universal Video Player are affected by CVE-2025-31917?
CVE-2025-31917 impacts LambertGroup Universal Video Player versions from n/a to 3.8.3 inclusive.
Is WordPress Universal Video Player also affected by CVE-2025-31917?
Yes, WordPress Universal Video Player versions from n/a to 3.8.3 are also vulnerable to CVE-2025-31917.
What can an attacker do with CVE-2025-31917?
An attacker can exploit CVE-2025-31917 to execute malicious scripts in the context of users accessing affected web pages.