JW-Player-Plugin-For-Wordpress <= 2.1.14 - Reflected Cross-Site Scripting
medium
The JW-Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 5.4
- Affected:
- up to 2.1.14
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2015
JW Player for Flash & HTML5 Video < 2.1.4 - Cross-Site Request Forgery leading to player deletion
medium
The JW Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on the player deletion functionality. This makes it possible for unauthenticated attackers to delete the plugin's players via forged request grante...
- CVSS:
- 4.3
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Jun 10, 2014
CVE-2014-4030 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database