🔐 CVE Alert

CVE-2025-7812

HIGH 8.8

Video Share VOD – Turnkey Video Site Builder Script <= 2.7.6 - Cross-Site Request Forgery to Command Injection

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.6. This is due to missing or incorrect nonce validation on the adminExport() function. This makes it possible for unauthenticated attackers to update settings and execute remote code when the Server command execution setting is enabled via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CWE CWE-352
Vendor videowhisper
Product video share vod – turnkey video site builder script
Published Aug 28, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for videowhisper video share vod – turnkey video site builder script

Be the first to know when new high vulnerabilities affecting videowhisper video share vod – turnkey video site builder script are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

videowhisper / Video Share VOD – Turnkey Video Site Builder Script
0 ≤ 2.7.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/b9e499c4-e683-4587-b0ab-7f4ecde94e41?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/video-share-vod/trunk/video-share-vod.php#L3360 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/video-share-vod/trunk/inc/options.php#L728 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3348480/video-share-vod/trunk/video-share-vod.php

Credits

Gai Tanaka