CVE-2025-53205: WordPress Radio Player Shoutcast & Icecast <= 4.4.7 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Radio Player Shoutcast & Icecast allows Reflected XSS. This issue affects Radio Player Shoutcast & Icecast: from n/a through 4.4.7.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Radio Player Shoutcast & Icecast lbg-audio4-html5-shoutcast allows Reflected XSS.This issue affects Radio Player Shoutcast & Icecast: from n/a through <= 4.4.7.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53205?
CVE-2025-53205 is a high severity vulnerability categorized as Cross-site Scripting (XSS).
How do I fix CVE-2025-53205?
To fix CVE-2025-53205, update the LambertGroup Radio Player Shoutcast & Icecast to version 4.4.8 or later that addresses this vulnerability.
What impact does CVE-2025-53205 have on my website?
CVE-2025-53205 can allow attackers to execute arbitrary JavaScript in the context of a user's session, potentially leading to data theft or unauthorized actions.
Which versions are affected by CVE-2025-53205?
CVE-2025-53205 affects LambertGroup Radio Player Shoutcast & Icecast versions from n/a up to and including 4.4.7.
Is CVE-2025-53205 a cumulative or incremental update?
CVE-2025-53205 is not a cumulative update and requires users to upgrade to the specific patched version to mitigate the vulnerability.