CVE-2025-26583: WordPress Video Share VOD plugin <= 2.7.9 - Reflected Cross-Site Scripting vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Video Share VOD video-share-vod allows Reflected XSS.This issue affects Video Share VOD: from n/a through <= 2.7.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26583?
CVE-2025-26583 is classified as a medium severity vulnerability due to its potential for exploitation through reflected cross-site scripting.
How do I fix CVE-2025-26583?
To fix CVE-2025-26583, update your Videowhisper Video Share VOD or WordPress Video Share VOD plugin to version 2.7.3 or later, which contains the necessary security patches.
What type of vulnerability is CVE-2025-26583?
CVE-2025-26583 is an improper neutralization of input vulnerability that leads to reflected cross-site scripting (XSS) in the affected software.
Which versions are affected by CVE-2025-26583?
CVE-2025-26583 affects Videowhisper Video Share VOD versions up to and including 2.7.2.
What impact does CVE-2025-26583 have on users?
Exploitation of CVE-2025-26583 can allow attackers to execute arbitrary JavaScript code in the context of a user's browser, potentially compromising user data.