plugin

Advanced Dewplayer Vulnerabilities

3 known security issues reported for the Advanced Dewplayer WordPress plugin. Most recent disclosed Mar 24, 2025.

2 high 1 medium

Running Advanced Dewplayer on your site? Check whether your installed version is affected.

Scan your site free

Advanced Dewplayer <= 1.6 - Missing Authorization

medium

The Advanced Dewplayer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.6
Fix:
No patched version reported
Disclosed:
Mar 24, 2025

CVE-2025-30592 on NVD →

Advanced Dewplayer < 1.3 - Directory Traversal

high

Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

CVSS:
7.5
Affected:
up to 1.2
Fixed in:
1.3
Disclosed:
Dec 30, 2013

CVE-2013-7240 on NVD →

Dewplayer <= 1.2 and Advanced Dewplayer < 1.5 - Content Spoofing/Injection

high

The Dewplayer plugin <= 1.2 and Advanced Dewplayer plugin < 1.5 for WordPress are vulnerable to Content Spoofing/Injection. This is due to lack of sanitization of the 'mp3', 'file', 'sound', and 'son' parameters in the dewplayer.swf file. This makes it possible for unauthenticated attackers to inject malicious content...

CVSS:
8.6
Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Dec 23, 2013

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database