In Target Video Easy Publish plugin for WordPress versions up to and including 3.8.5 a medium severity vulnerability CVE-2025-5237 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘width’ parameter due to insufficient input sanitization and output escaping. To address this issue, users should update Target Video Easy Publish plugin to versions 3.8.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5237.
WordPress: Stored XSS Vulnerability in Target Video Easy Publish Plugin
by the Hossted team
18.06.2025