Dewplayer <= 1.2 - Cross-Site Scripting
medium
The Dewplayer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on the XML file supplied via the xml parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...
- CVSS:
- 6.1
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 23, 2014
Dewplayer <= 1.2 and Advanced Dewplayer < 1.5 - Content Spoofing/Injection
high
The Dewplayer plugin <= 1.2 and Advanced Dewplayer plugin < 1.5 for WordPress are vulnerable to Content Spoofing/Injection. This is due to lack of sanitization of the 'mp3', 'file', 'sound', and 'son' parameters in the dewplayer.swf file. This makes it possible for unauthenticated attackers to inject malicious content...
- CVSS:
- 8.6
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Dec 23, 2013
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database