CVE-2025-53559: WordPress Universal Video Player - Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder allows Reflected XSS. This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through 3.2.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53559?
The severity of CVE-2025-53559 is considered high due to the potential for reflected XSS attacks.
How do I fix CVE-2025-53559?
To fix CVE-2025-53559, update the Universal Video Player - Addon for WPBakery Page Builder to version 3.2.2 or later.
What kind of attacks can CVE-2025-53559 facilitate?
CVE-2025-53559 can facilitate reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
What versions of the Universal Video Player are affected by CVE-2025-53559?
CVE-2025-53559 affects Universal Video Player - Addon for WPBakery Page Builder versions up to and including 3.2.1.
Who is the vendor responsible for CVE-2025-53559?
The vendor responsible for CVE-2025-53559 is LambertGroup.