plugin

Jw Player Plugin For Wordpress Vulnerabilities

2 known security issues reported for the Jw Player Plugin For Wordpress WordPress plugin. Most recent disclosed Nov 21, 2015.

2 medium

Running Jw Player Plugin For Wordpress on your site? Check whether your installed version is affected.

Scan your site free

JW-Player-Plugin-For-Wordpress <= 2.1.14 - Reflected Cross-Site Scripting

medium

The JW-Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
5.4
Affected:
up to 2.1.14
Fix:
No patched version reported
Disclosed:
Nov 21, 2015

JW Player for Flash & HTML5 Video < 2.1.4 - Cross-Site Request Forgery leading to player deletion

medium

The JW Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on the player deletion functionality. This makes it possible for unauthenticated attackers to delete the plugin's players via forged request grante...

CVSS:
4.3
Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Jun 10, 2014

CVE-2014-4030 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database