Junglewise Threat Intelligence

CVE-2025-62143: nicashmu Post Video Players sensitive data exposure

CVE-2025-62143 · Severity: medium · CVSS 4.3 · Published 2025-12-31

Executive brief

The Post Video Players WordPress plugin contains a flaw that exposes sensitive system information to unauthorized parties. An attacker with contributor-level privileges could retrieve embedded sensitive data such as passwords, emails, or payment details that should remain private, potentially compromising user accounts and data security on affected WordPress sites.

Technical details

This is a sensitive data exposure vulnerability (CWE-200) in the Post Video Players WordPress plugin affecting versions up to 1.165. The vulnerability allows retrieval of embedded sensitive data and requires contributor-level privileges to exploit. The exact mechanism and scope of exposed data are not detailed in available sources, but the impact includes potential exposure of private information including passwords, emails, and payment details. No official patch is currently available; users should update to a patched version when available.

Affected products

  • nicashmu Post Video Players <= 1.165

Timeline

  • 2025-10-27: disclosed: Reported by Nabil Irawan
  • 2025-12-31: advisory: Published by Patchstack and disclosed on NVD

References