Executive brief
Presto Player, a popular video player plugin for WordPress, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of visitors or the theft of sensitive session information.
Technical details
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the getOverlays() function. Specifically, the 'link_url' attribute of the [presto_player_overlay] shortcode is copied directly into the overlay configuration without proper scheme validation. This allows 'javascript:' URIs to be rendered as the href attribute of a clickable anchor element within the presto-dynamic-overlay-ui web component. Authenticated attackers with contributor-level permissions or higher can exploit this to inject arbitrary web scripts. The vulnerability is present in versions up to and including 4.2.0 and has been addressed in subsequent updates.
Affected products
- Presto Made Presto Player up to, and including, 4.2.0
Timeline
- 2026-06-12: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/presto-player/tags/4.1.1/dist/components/collection/components/core/features/presto-dynamic-overlays/component/presto-dynamic-overlays.js
- https://plugins.trac.wordpress.org/browser/presto-player/tags/4.1.1/inc/Services/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/presto-player/tags/4.1.1/inc/Services/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/presto-player/tags/4.1.1/templates/video.php
- https://plugins.trac.wordpress.org/browser/presto-player/tags/4.1.4/dist/components/collection/components/core/features/presto-dynamic-overlays/component/presto-dynamic-overlays.js
- https://plugins.trac.wordpress.org/browser/presto-player/tags/4.1.4/inc/Services/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/presto-player/tags/4.1.4/inc/Services/Shortcodes.php