CNNVD-202512-5583 Information

CNNVD ID

CNNVD-202512-5583

CVE-2025-62143

  • CNNVD Published: 2025-12-31

Description (Chinese)

Expo等都是(Expo)的产品。Expo是WebSockets ws等都是(WebSockets)开源的产品。ws是一个 Node.js WebSocket 库。TanStack form等都是(TanStack)开源的产品。form是一个表单状态管理程序。 WordPress plugin Post Video Players 1.163及之前版本存在安全漏洞,该漏洞源于向未授权控制范围暴露敏感系统信息,可能导致检索嵌入式敏感数据。

Description (English)

Expo and others are products of Expo. Expo is a product of WebSockets ws and so on. Ws is a Node.js WebSocket library. TanStack form and so on are open-source products. Form is a form status management program. WordPress Plugin Post Video Players 1.163 and previous versions have a security loophole, which stems from the exposure of sensitive system information to unauthorized control and may lead to the retrieval of embedded sensitive data.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

WordPress

Published

2025-12-31

Last Modified

2026-02-24

References

https://vdp.patchstack.com/database/wordpress/plugin/video-playlist-and-gallery-plugin/vulnerability/wordpress-post-video-players-plugin-1-163-sensitive-data-exposure-vulnerability?_s_id=cve

Share on: