plugin

Dewplayer Flash Mp3 Player Vulnerabilities

2 known security issues reported for the Dewplayer Flash Mp3 Player WordPress plugin. Most recent disclosed Dec 23, 2014.

1 high 1 medium

Running Dewplayer Flash Mp3 Player on your site? Check whether your installed version is affected.

Scan your site free

Dewplayer <= 1.2 - Cross-Site Scripting

medium

The Dewplayer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on the XML file supplied via the xml parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...

CVSS:
6.1
Affected:
up to 1.2
Fix:
No patched version reported
Disclosed:
Dec 23, 2014

Dewplayer <= 1.2 and Advanced Dewplayer < 1.5 - Content Spoofing/Injection

high

The Dewplayer plugin <= 1.2 and Advanced Dewplayer plugin < 1.5 for WordPress are vulnerable to Content Spoofing/Injection. This is due to lack of sanitization of the 'mp3', 'file', 'sound', and 'son' parameters in the dewplayer.swf file. This makes it possible for unauthenticated attackers to inject malicious content...

CVSS:
8.6
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Dec 23, 2013

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database