Luna Radio Player [lu-radioplayer] < 6.24.11.15
unknown
[en] The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribu...
- Affected:
- up to 6.24.11.15
- Fixed in:
- 6.24.11.15
- Disclosed:
- Dec 5, 2024
CVE-2024-10881 on NVD →
LUNA RADIO PLAYER <= 6.24.11.07 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 6.24.11.07
- Fixed in:
- 6.24.11.15
- Disclosed:
- Nov 15, 2024
CVE-2024-10881 on NVD →
Luna Radio Player [lu-radioplayer] < 6.24.11.07
unknown
[en] The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected:
- up to 6.24.11.07
- Fixed in:
- 6.24.11.07
- Disclosed:
- Nov 13, 2024
CVE-2024-10816 on NVD →
LUNA RADIO PLAYER <= 6.24.01.24 - Unauthenticated Arbitrary File Read
high
The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 6.24.01.24
- Fixed in:
- 6.24.11.07
- Disclosed:
- Nov 12, 2024
CVE-2024-10816 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database