Junglewise Threat Intelligence

CVE-2026-9125: Presto Player Stored XSS in presto_player_overlay shortcode

CVE-2026-9125 · Severity: medium · CVSS 6.4 · Published 2026-06-12

Executive brief

Presto Player, a popular video player plugin for WordPress, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of visitors or the theft of sensitive session information.

Technical details

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the getOverlays() function. Specifically, the 'link_url' attribute of the [presto_player_overlay] shortcode is copied directly into the overlay configuration without proper scheme validation. This allows 'javascript:' URIs to be rendered as the href attribute of a clickable anchor element within the presto-dynamic-overlay-ui web component. Authenticated attackers with contributor-level permissions or higher can exploit this to inject arbitrary web scripts. The vulnerability is present in versions up to and including 4.2.0 and has been addressed in subsequent updates.

Affected products

  • Presto Made Presto Player up to, and including, 4.2.0

Timeline

  • 2026-06-12: advisory: NVD publication date

References