CVE-2025-32123: WordPress HTML5 Video Player with Playlist & Multiple Skins plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Video Player with Playlist & Multiple Skins lbg-vp2-html5-rightside allows Reflected XSS.This issue affects HTML5 Video Player with Playlist & Multiple Skins: from n/a through <= 5.3.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32123?
CVE-2025-32123 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-32123?
To fix CVE-2025-32123, update the HTML5 Video Player with Playlist & Multiple Skins plugin to version 5.3.6 or later.
What are the risks associated with CVE-2025-32123?
The risks of CVE-2025-32123 include unauthorized access to user data and redirecting users to malicious sites.
Which versions are affected by CVE-2025-32123?
CVE-2025-32123 affects all versions of the HTML5 Video Player with Playlist & Multiple Skins plugin up to and including version 5.3.5.
Is CVE-2025-32123 related to WordPress security?
Yes, CVE-2025-32123 impacts WordPress sites using the affected plugin, making it a significant concern for WordPress security.