CVE-2025-48154: WordPress Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin <= 2.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder allows Reflected XSS. This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder: from n/a through 2.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbgvpyoutubevimeoaddonvisualcomposer allows Reflected XSS.This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder: from n/a through <= 2.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48154?
CVE-2025-48154 has a high severity rating due to its potential for providing attackers with the ability to execute malicious scripts through reflected XSS.
How do I fix CVE-2025-48154?
To fix CVE-2025-48154, update the Multimedia Playlist Slider Addon for WPBakery Page Builder to version 2.1 or later.
Which versions are affected by CVE-2025-48154?
CVE-2025-48154 affects all versions of the Multimedia Playlist Slider Addon for WPBakery Page Builder up to and including version 2.1.
What type of attack does CVE-2025-48154 facilitate?
CVE-2025-48154 facilitates reflected cross-site scripting (XSS) attacks allowing for the execution of arbitrary scripts in users' browsers.
Who is impacted by CVE-2025-48154?
Users of the Multimedia Playlist Slider Addon for WPBakery Page Builder, especially those running versions up to 2.1, are impacted by CVE-2025-48154.