CVE-2025-62142
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicashmu Post Video Players video-playlist-and-gallery-plugin allows Stored XSS.This issue affects Post Video Players: from n/a through <= 1.163.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS vulnerability in WordPress Post Video Players plugin allows authenticated attackers to inject malicious scripts, affecting versions up to 1.163.
Vulnerability
Description The Post Video Players plugin for WordPress suffers from a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This issue affects all versions up to and including 1.163.
Exploitation
Exploitation requires an authenticated user with contributor-level access or higher to inject malicious script code into post or page content [1]. The injected script is stored on the server and executed when other users, including site visitors, access the affected page. Successful exploitation depends on a privileged user performing an action, such as clicking a malicious link or visiting a crafted page.
Impact
An attacker can leverage this vulnerability to inject arbitrary JavaScript, which may result in redirections, advertisements, or other HTML payloads [1]. This can compromise the integrity of the website and potentially lead to data theft or further attacks against site visitors.
Mitigation
The vendor has released a patched version of the plugin. Users are strongly advised to update to the latest version immediately [1]. If updating is not possible, consider implementing temporary workarounds such as disabling the plugin or enforcing strict input validation and output encoding.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.163
- Range: <=1.163
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.