plugin

Blaze Slide Show For Wordpress Vulnerabilities

11 known security issues reported for the Blaze Slide Show For Wordpress WordPress plugin. Most recent disclosed Jul 27, 2023.

2 critical 1 medium

Running Blaze Slide Show For Wordpress on your site? Check whether your installed version is affected.

Scan your site free

Blaze Slideshow [blaze-slide-show-for-wordpress] < 1.1

unknown

Update the plugin. MustLive discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Blaze Slideshow Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit you...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2023

Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.2

unknown

Update plugin. An unknown person discovered and reported this Other Vulnerability Type vulnerability in WordPress Blaze Slideshow Plugin. This vulnerability has been fixed in version 2.2.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
May 15, 2023

Blaze Slideshow [blaze-slide-show-for-wordpress] < 1.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2016

Blaze Slide Show <= 2.7 - Arbitrary File upload

critical

The Blaze Slide Show plugin for Wordpress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_admin_request()' function in versions up to, and including, 2.7. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code ex...

CVSS:
9.8
Affected:
up to 2.7
Fix:
No patched version reported
Disclosed:
Jun 7, 2016

Blaze Slideshow [blaze-slide-show-for-wordpress] <= 2.7 (unfixed)

unknown

The Blaze Slide Show plugin for Wordpress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_admin_request()' function in versions up to, and including, 2.7. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code ex...

Affected:
up to 2.7
Fix:
No patched version reported
Disclosed:
Jun 7, 2016

Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.2 (closed)

unknown

This plugin is prone to an unspecified security vulnerability. Update plugin.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
May 15, 2015

Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.6

unknown

[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Jul 19, 2013

CVE-2012-3414 on NVD →

SWFUpload <= 2.2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
6.1
Affected:
up to 2.4
Fixed in:
2.6
Disclosed:
Nov 9, 2012

CVE-2012-3414 on NVD →

Blaze Slideshow <= 2.4 - Arbitrary File Upload

critical

The Blaze Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/js/swfupload/js/upload.php' file in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may mak...

CVSS:
9.8
Affected:
up to 2.4
Fixed in:
2.6
Disclosed:
Jan 6, 2012

Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.6

unknown

The Blaze Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/js/swfupload/js/upload.php' file in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may mak...

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Jan 6, 2012

Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.2 (closed)

unknown

The blaze-slide-show-for-wordpress WordPress plugin was affected by an Unspecified Security security vulnerability.

Affected:
up to 2.2
Fixed in:
2.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database