plugin

Contus Video Comments Vulnerabilities

5 known security issues reported for the Contus Video Comments WordPress plugin. Most recent disclosed Oct 6, 2016.

1 critical 1 medium

Running Contus Video Comments on your site? Check whether your installed version is affected.

Scan your site free

CONTUS VIDEO COMMENTS [contus-video-comments] < 1.1

unknown

[en] Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Oct 6, 2016

CVE-2016-1000112 on NVD →

Contus Video Comments <= 1.0 - Remote File Upload

critical

The Contus Video Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Jun 22, 2016

CVE-2016-1000112 on NVD →

Contus Video Comments <= 1.0 - Authorization Bypass

medium

The Contus Video Comments plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the file_put_contents function in versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to upload .jpg images anywhere in the WordPress installation.

CVSS:
5.3
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Jun 15, 2016

CONTUS VIDEO COMMENTS [contus-video-comments] <= 1.0 (unfixed)

unknown

The Contus Video Comments plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the file_put_contents function in versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to upload .jpg images anywhere in the WordPress installation.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Jun 15, 2016

CONTUS VIDEO COMMENTS [contus-video-comments] <= 1.0 (unfixed + closed)

unknown

The contus-video-comments WordPress plugin was affected by an Unauthenticated Remote JPG File Upload security vulnerability.

Affected:
up to 1.0
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database