VYPR
High severity7.1NVD Advisory· Published Aug 20, 2025· Updated Apr 23, 2026

CVE-2025-53563

CVE-2025-53563

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slider video_player_youtube_vimeo allows Reflected XSS.This issue affects Youtube Vimeo Video Player and Slider: from n/a through <= 3.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in WordPress Youtube Vimeo Video Player and Slider plugin (≤3.8) allows script injection via unneutralized input.

Improper neutralization of user-supplied input in the LambertGroup Youtube Vimeo Video Player and Slider plugin for WordPress leads to a reflected cross-site scripting (XSS) vulnerability. The issue affects versions from n/a through 3.8 of the video_player_youtube_vimeo plugin. The root cause is a failure to sanitize or escape input before including it in web page output, enabling an attacker to inject arbitrary JavaScript or HTML into the response [1].

Exploitation

Exploitation requires user interaction: a victim with sufficient privileges (e.g., an administrator) must click a crafted link, visit a malicious page, or submit a specially prepared form. No authentication is needed to initiate the attack vector, but the target user must perform the action. The reflected XSS can be delivered via a URL that includes the malicious payload, which is then executed in the context of the victim's session [1].

Impact

Successful exploitation allows the attacker to inject scripts that can perform actions such as redirecting visitors to malicious sites, displaying unwanted advertisements, or exfiltrating sensitive data. The CVSS v3.1 score of 7.1 (High) underscores the risk, and the vulnerability is considered moderately dangerous, with expected mass-exploit campaigns targeting numerous WordPress sites regardless of size [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.