CVE-2025-69048: WordPress Universal Video Player plugin <= 3.8.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player universal-video-player allows Reflected XSS.This issue affects Universal Video Player: from n/a through <= 3.8.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69048?
CVE-2025-69048 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-69048?
To fix CVE-2025-69048, update the Universal Video Player plugin to version 3.8.5 or higher.
What type of vulnerability is CVE-2025-69048?
CVE-2025-69048 is a reflected cross-site scripting (XSS) vulnerability found in the Universal Video Player plugin.
Which versions of the Universal Video Player are affected by CVE-2025-69048?
CVE-2025-69048 affects versions of the Universal Video Player plugin up to and including 3.8.4.
What is the impact of exploiting CVE-2025-69048?
Exploiting CVE-2025-69048 can allow attackers to inject malicious scripts into web pages, potentially compromising user data and site integrity.