CVE-2025-32516: WordPress Related Videos for JW Player plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ilGhera Related Videos for JW Player allows Reflected XSS. This issue affects Related Videos for JW Player: from n/a through 1.2.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ilGhera Related Videos for JW Player related-videos-for-jw-player allows Reflected XSS.This issue affects Related Videos for JW Player: from n/a through <= 1.2.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32516?
CVE-2025-32516 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-32516?
To fix CVE-2025-32516, update the ilGhera Related Videos for JW Player plugin to version 1.2.1 or later.
What versions are affected by CVE-2025-32516?
CVE-2025-32516 affects all versions of ilGhera Related Videos for JW Player up to and including 1.2.0.
What software is impacted by CVE-2025-32516?
CVE-2025-32516 impacts ilGhera Related Videos for JW Player and WordPress Related Videos for JW Player.
Can CVE-2025-32516 be exploited by an attacker?
Yes, CVE-2025-32516 can be exploited by an attacker to execute malicious scripts in the user's browser.