CVE-2025-48168: WordPress Apollo - Sticky Full Width HTML5 Audio Player <= 3.4 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Audio Player allows Reflected XSS. This issue affects Apollo - Sticky Full Width HTML5 Audio Player: from n/a through 3.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Audio Player lbg-audio5-html5-shoutcast-sticky allows Reflected XSS.This issue affects Apollo - Sticky Full Width HTML5 Audio Player: from n/a through <= 3.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48168?
CVE-2025-48168 has a medium severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-48168?
To fix CVE-2025-48168, update the Apollo - Sticky Full Width HTML5 Audio Player to version 3.4 or later.
What software is affected by CVE-2025-48168?
CVE-2025-48168 affects versions of Apollo - Sticky Full Width HTML5 Audio Player up to and including 3.4.
Can CVE-2025-48168 lead to data breaches?
Yes, CVE-2025-48168 can potentially lead to data breaches through successful XSS attacks.
Who is the vendor for CVE-2025-48168?
The vendor for CVE-2025-48168 is LambertGroup.