CVE-2025-54056: WordPress Responsive HTML5 Audio Player PRO With Playlist <= 3.5.8 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist allows Reflected XSS. This issue affects Responsive HTML5 Audio Player PRO With Playlist: from n/a through 3.5.8.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist lbg-audio2-html5 allows Reflected XSS.This issue affects Responsive HTML5 Audio Player PRO With Playlist: from n/a through <= 3.5.8.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54056?
CVE-2025-54056 has a moderate severity level due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-54056?
To fix CVE-2025-54056, update the Responsive HTML5 Audio Player PRO With Playlist to version 3.5.9 or later.
What versions are affected by CVE-2025-54056?
CVE-2025-54056 affects all versions of Responsive HTML5 Audio Player PRO With Playlist from n/a up to and including 3.5.8.
Where can I find more information about CVE-2025-54056?
Information about CVE-2025-54056 can typically be found in security advisories or vulnerability databases.
Who is the vendor for the product affected by CVE-2025-54056?
The vendor for the affected product is LambertGroup.