1player [1player] < 1.4 (closed)
unknownBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- May 15, 2015
plugin
4 known security issues reported for the 1Player WordPress plugin. Most recent disclosed May 15, 2015.
Running 1Player on your site? Check whether your installed version is affected.
Scan your site freeBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.
The S3 Video, EasySqueezePage, External "Video for Everybody", Videopack, and 1player plugins for WordPress are vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of VideoJS in various versions due to insufficient input sanitization and output escaping. This makes it possible for unau...
The S3 Video, EasySqueezePage, External "Video for Everybody", Videopack, and 1player plugins for WordPress are vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of VideoJS in various versions due to insufficient input sanitization and output escaping. This makes it possible for unau...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free