CVE-2025-53564: WordPress HTML5 Radio Player - WPBakery Page Builder Addon <= 2.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon allows Reflected XSS. This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from n/a through 2.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon lbgradioplayeraddonvisualcomposer allows Reflected XSS.This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from n/a through <= 2.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53564?
CVE-2025-53564 has a medium severity level, indicating a potential risk of reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-53564?
To mitigate CVE-2025-53564, update the HTML5 Radio Player - WPBakery Page Builder Addon to version 2.6 or later.
What impact does CVE-2025-53564 have on my website?
CVE-2025-53564 could allow attackers to execute malicious scripts in the context of your users' browsers.
Which versions of the HTML5 Radio Player - WPBakery Page Builder Addon are affected by CVE-2025-53564?
CVE-2025-53564 affects versions of the HTML5 Radio Player - WPBakery Page Builder Addon up to and including version 2.5.
Is CVE-2025-53564 a supported vulnerability with patches?
Yes, CVE-2025-53564 is supported with patches in the updated version of the plugin.