VYPR
High severity7.1NVD Advisory· Published Aug 20, 2025· Updated Apr 23, 2026

CVE-2025-53562

CVE-2025-53562

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg_universal_video_player_addon_visual_composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder: from n/a through <= 3.2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected XSS vulnerability in the Universal Video Player addon for WPBakery Page Builder (≤3.2.1) allows attackers to inject malicious scripts via unvalidated input.

The lbg_universal_video_player_addon_visual_composer WordPress plugin for WPBakery Page Builder contains a reflected cross-site scripting (XSS) flaw due to improper neutralization of user-supplied input during web page generation [1]. This vulnerability affects plugin versions from n/a through 3.2.1, and is classified with a CVSS score of 7.1 (High) [1].

Exploitation requires an authenticated user with sufficient privileges to perform an action, such as clicking a crafted link, visiting a malicious page, or submitting a specially designed form [1]. An attacker who successfully tricks a privileged user into interacting with a crafted URL can inject arbitrary HTML or JavaScript into the generated page [1].

The injected script executes in the context of the victim's browser session, enabling actions such as redirecting visitors to malicious sites, displaying unauthorized advertisements, or exfiltrating sensitive data [1]. This vulnerability is considered moderately dangerous and is expected to be targeted in mass-exploit campaigns against WordPress sites [1].

The vendor has released version 3.2.2.0 which resolves the issue; users are strongly advised to update immediately [1]. For those unable to update, applying a virtual patch or mitigation rule (such as those provided by Patchstack) can block exploitation attempts until the plugin is updated [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.