Blaze Slideshow [blaze-slide-show-for-wordpress] < 1.1
unknown
Update the plugin.
MustLive discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Blaze Slideshow Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit you...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 27, 2023
Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.2
unknown
Update plugin.
An unknown person discovered and reported this Other Vulnerability Type vulnerability in WordPress Blaze Slideshow Plugin. This vulnerability has been fixed in version 2.2.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- May 15, 2023
Blaze Slideshow [blaze-slide-show-for-wordpress] < 1.1 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 27, 2016
Blaze Slide Show <= 2.7 - Arbitrary File upload
critical
The Blaze Slide Show plugin for Wordpress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_admin_request()' function in versions up to, and including, 2.7. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code ex...
- CVSS:
- 9.8
- Affected:
- up to 2.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 7, 2016
Blaze Slideshow [blaze-slide-show-for-wordpress] <= 2.7 (unfixed)
unknown
The Blaze Slide Show plugin for Wordpress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_admin_request()' function in versions up to, and including, 2.7. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code ex...
- Affected:
- up to 2.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 7, 2016
Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.2 (closed)
unknown
This plugin is prone to an unspecified security vulnerability.
Update plugin.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- May 15, 2015
Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.6
unknown
[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Jul 19, 2013
CVE-2012-3414 on NVD →
SWFUpload <= 2.2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 6.1
- Affected:
- up to 2.4
- Fixed in:
- 2.6
- Disclosed:
- Nov 9, 2012
CVE-2012-3414 on NVD →
Blaze Slideshow <= 2.4 - Arbitrary File Upload
critical
The Blaze Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/js/swfupload/js/upload.php' file in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may mak...
- CVSS:
- 9.8
- Affected:
- up to 2.4
- Fixed in:
- 2.6
- Disclosed:
- Jan 6, 2012
Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.6
unknown
The Blaze Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/js/swfupload/js/upload.php' file in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may mak...
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Jan 6, 2012
Blaze Slideshow [blaze-slide-show-for-wordpress] < 2.2 (closed)
unknown
The blaze-slide-show-for-wordpress WordPress plugin was affected by an Unspecified Security security vulnerability.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database