CVE-2025-53212

7.1

LambertGroup · Revolution Video Player With Bottom Playlist

A reflected cross-site scripting (XSS) vulnerability exists in the LambertGroup Revolution Video Player plugin, allowing attackers to inject malicious scripts via unsanitized input.

Executive summary

A reflected XSS vulnerability in the LambertGroup Revolution Video Player plugin allows unauthenticated attackers to execute arbitrary scripts in the context of a user session.

Vulnerability

This is a reflected cross-site scripting (CWE-79) vulnerability occurring due to improper neutralization of input during web page generation. An unauthenticated attacker can trigger the execution of malicious scripts by tricking a user into interacting with a crafted URL.

Business impact

The exploitation of this vulnerability could lead to session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious websites. With a CVSS score of 7.1, the risk is classified as High, reflecting the potential for significant disruption to site integrity and user trust despite the requirement for user interaction.

Remediation

Immediate Action: Since no specific patch version is currently confirmed, administrators should disable or remove the Revolution Video Player With Bottom Playlist plugin until a security update is released by the vendor.

Proactive Monitoring: Review web server access logs for anomalous request patterns or URL parameters containing script-like characters, such as