CVE-2025-2484

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 22, 2025
CWE ID 288

Summary

CVE-2025-2484 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Multi Video Box plugin for WordPress. Versions up to and including 1.5.2 are impacted by the issue. The vulnerability arises due to insufficient input sanitization and output escaping in the handling of the 'video_id' and 'group_id' parameters. This flaw allows unauthenticated attackers to inject arbitrary web scripts into pages, which can be executed if a user is tricked into taking a specific action, such as clicking on a malicious link. Successful exploitation of this vulnerability can lead to the theft of sensitive user information or the installation of malware. Users are urged to update the plugin to a version free of this issue as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share