CVE-2025-53563
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slider video_player_youtube_vimeo allows Reflected XSS.This issue affects Youtube Vimeo Video Player and Slider: from n/a through <= 3.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in WordPress Youtube Vimeo Video Player and Slider plugin (≤3.8) allows script injection via unneutralized input.
Improper neutralization of user-supplied input in the LambertGroup Youtube Vimeo Video Player and Slider plugin for WordPress leads to a reflected cross-site scripting (XSS) vulnerability. The issue affects versions from n/a through 3.8 of the video_player_youtube_vimeo plugin. The root cause is a failure to sanitize or escape input before including it in web page output, enabling an attacker to inject arbitrary JavaScript or HTML into the response [1].
Exploitation
Exploitation requires user interaction: a victim with sufficient privileges (e.g., an administrator) must click a crafted link, visit a malicious page, or submit a specially prepared form. No authentication is needed to initiate the attack vector, but the target user must perform the action. The reflected XSS can be delivered via a URL that includes the malicious payload, which is then executed in the context of the victim's session [1].
Impact
Successful exploitation allows the attacker to inject scripts that can perform actions such as redirecting visitors to malicious sites, displaying unwanted advertisements, or exfiltrating sensitive data. The CVSS v3.1 score of 7.1 (High) underscores the risk, and the vulnerability is considered moderately dangerous, with expected mass-exploit campaigns targeting numerous WordPress sites regardless of size [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=3.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.