Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player allows Reflected XSS. This issue affects Universal Video Player: from n/a through 1.4.0.CreditsTran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)Referenceshttps://patchstack.com/database/wordpress/plugin/elementor_widget_universal_video_player/vulnerability/wordpress-universal-video-player-plugin-1-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve