CVE-2025-53212: WordPress Revolution Video Player With Bottom Playlist <= 2.9.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Revolution Video Player With Bottom Playlist allows Reflected XSS. This issue affects Revolution Video Player With Bottom Playlist: from n/a through 2.9.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Revolution Video Player With Bottom Playlist revolution-video-player allows Reflected XSS.This issue affects Revolution Video Player With Bottom Playlist: from n/a through <= 2.9.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53212?
CVE-2025-53212 is classified with a medium severity due to its potential for exploitation via reflected XSS attacks.
How do I fix CVE-2025-53212?
To fix CVE-2025-53212, update the Revolution Video Player With Bottom Playlist to version 2.9.3 or later.
Which versions are affected by CVE-2025-53212?
CVE-2025-53212 affects all versions of the Revolution Video Player With Bottom Playlist from n/a through 2.9.2.
What type of vulnerability is CVE-2025-53212?
CVE-2025-53212 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Is the vulnerability specific to certain platforms in CVE-2025-53212?
Yes, CVE-2025-53212 affects both the LambertGroup and WordPress implementations of the Revolution Video Player With Bottom Playlist.