PT-2025-54321 · WordPress · Cincopa Video/Media Plug-In
Nabil Irawan
·
Published
2025-12-31
·
Updated
2026-01-01
·
CVE-2025-62142
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cincopa video and media plugin versions through 1.163
Description
The Cincopa video and media plugin contains a flaw related to improper input handling during web page generation, which allows for Stored Cross-site Scripting (XSS). This means that malicious scripts can be injected into web pages and executed by unsuspecting users. The affected plugin is used for embedding video and media content. The vulnerability allows an attacker to inject malicious code that could compromise user accounts or deface websites.
Recommendations
Update to a version beyond 1.163. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cincopa Video/Media Plug-In