CVE-2025-0692

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Feb 13, 2025
Updated: Feb 19, 2025

Summary

CVE-2025-0692 is a vulnerability affecting the Simple Video Management System plugin for WordPress. The issue lies in the plugin's failure to sanitize and escape certain settings. This oversight permits high privilege users, including admins, to execute Stored Cross-Site Scripting (XSS) attacks, even when the unfiltered_html capability is disabled in multisite setups. The vulnerability poses a significant risk, as successful exploitation could lead to unauthorized access or data theft. It is essential for users of the Simple Video Management System plugin to update to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share