CVE-2025-54016 Information

Description

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Kyle Gilman Videopack allows DOM-Based XSS. This issue affects Videopack: from n/a through 4.10.3.

Reference

https://patchstack.com/database/wordpress/plugin/video-embed-thumbnail-generator/vulnerability/wordpress-videopack-plugin-4-10-3-cross-site-scripting-xss-vulnerability?_s_id=cve

CNNVD-202507-2156 (Published: 2025-07-16)

Share on: