Flash player widget <= 1.3 - Content Spoofing
mediumThe Flash player widget plugin for WordPress is vulnerable to Content Spoofing in versions up to, and including, 1.3. This is due to insufficient sanitization of user input on the 'mp3' parameter. This makes it possible for unauthenticated attackers to to inject arbitrary content in pages if they can successfully trick...
- CVSS:
- 4.7
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2013