CVE-2025-48159

7.1

LambertGroup · Youtube Vimeo Video Player and Slider WP Plugin

A reflected cross-site scripting (XSS) vulnerability exists in the Youtube Vimeo Video Player and Slider WP Plugin due to improper neutralization of user-supplied input.

Executive summary

A reflected cross-site scripting vulnerability in the LambertGroup Youtube Vimeo Video Player and Slider WP Plugin allows unauthenticated attackers to execute arbitrary scripts in a user's browser.

Vulnerability

The plugin fails to properly sanitize input during web page generation, leading to a reflected XSS vulnerability. An unauthenticated attacker can craft malicious links that, when clicked by a victim, execute unauthorized JavaScript within the context of the victim's session.

Business impact

Successful exploitation allows an attacker to steal session cookies, capture sensitive user data, or perform unauthorized actions on behalf of the victim. With a CVSS score of 7.1, this vulnerability poses a significant risk to the integrity and confidentiality of user interactions within the WordPress environment.

Remediation

Immediate Action: Since no specific patch version is currently identified, administrators should immediately deactivate or uninstall the Youtube Vimeo Video Player and Slider WP Plugin until a secure version is released by the vendor.

Proactive Monitoring: Review web server and WordPress access logs for anomalous requests containing script tags or suspicious URL parameters directed at the plugin directory.

Compensating Controls: Deploy a Web Application Firewall (WAF) with robust XSS filtering rules to block malicious payloads targeting the plugin's vulnerable input parameters.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the High severity score, the risk of unauthorized access is substantial. Organizations utilizing this plugin must prioritize its removal or restriction to prevent potential exploitation until a verified security update becomes available from the developer.

More LambertGroup CVEs

Sources

Originally found and disclosed by 0xd4rk5id3 | Patchstack Bug Bounty Program, per the CVE Program record.