CVE-2026-102914: WordPress Presto Player plugin <= 4.5.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/presto-playerto a version that resolves this vulnerability.Fixed in 4.5.3
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability requires network access, low-level privileges, and user interaction. An attacker must be able to act as a low-privileged user and induce a user to view or interact with the malicious stored content.
What is the potential impact if exploitation succeeds?
Successful exploitation can execute stored cross-site scripting in a victim's browser. The reported vector indicates low impacts to confidentiality, integrity, and availability, with scope changed.
Which Presto Player versions are affected?
Presto Player versions through 4.5.2 are affected. The available information does not identify a fixed version.