MP3-jPlayer [mp3-jplayer] < 2.3.4 (closed)
unknown
Update the plugin.
Larry W. Cashdollar discovered and reported this Full Path Disclosure (FPD) vulnerability in WordPress MP3 jPlayer Plugin. This vulnerability has been fixed in version 2.3.4.
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Aug 6, 2023
MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)
unknown
Update the plugin.
HauntIT Blog discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit you...
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Aug 1, 2023
MP3-jPlayer [mp3-jplayer] < 1.8 (closed)
unknown
Upgrade this plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Aug 1, 2023
MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)
unknown
Upgrade this plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Aug 1, 2023
MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)
unknown
Upgrade this plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Aug 1, 2023
MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)
unknown
Upgrade this plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Aug 1, 2023
MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)
unknown
Update the plugin.
HauntIT Blog discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit you...
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Aug 1, 2023
MP3-jPlayer [mp3-jplayer] < 2.4 (closed)
unknown
Update the plugin.
KedAns-Dz discovered and reported this Local File Inclusion vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentiall...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Mar 23, 2023
MP3-jPlayer [mp3-jplayer] < 2.4 (closed)
unknown
Update the plugin.
KedAns-Dz discovered and reported this Local File Inclusion vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentiall...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Mar 23, 2023
MP3 jPlayer <= 2.7.3 - Cross-Site Request Forgery
high
The MP3 jPlayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.3. This is due to missing or incorrect nonce validation on several of its functions. This makes it possible for unauthenticated attackers to execute them, via forged request granted they can trick a si...
- CVSS:
- 8.8
- Affected:
- up to 2.7.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 1, 2022
CVE-2022-36373 on NVD →
MP3-jPlayer [mp3-jplayer] <= 2.7.3 (unfixed + closed)
unknown
[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress.
- Affected:
- up to 2.7.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 1, 2022
CVE-2022-36373 on NVD →
MP3-jPlayer [mp3-jplayer] < 2.5 (unfixed + closed)
unknown
[en] Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2
- Affected:
- up to 2.5
- Fix:
- No patched version reported
- Disclosed:
- Oct 6, 2016
CVE-2015-1000008 on NVD →
MP3-jPlayer [mp3-jplayer] < 2.3.4 (closed)
unknown
Because of this vulnerability, attackers can disclose path information on wordpress sites.
Update the plugin.
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Aug 6, 2015
MP3-jPlayer <= 2.4.2 - Full Path Disclosure
medium
The MP3-jPlayer plugin for WordPress is vulnerable to Path Disclosure in versions before 2.5.
- CVSS:
- 5.3
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- Jul 12, 2015
CVE-2015-1000008 on NVD →
MP3-jPlayer [mp3-jplayer] < 2.4 (closed)
unknown
Because of this vulnerability, attackers can download or disclosure file's from the root-path.
Update the plugin.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Mar 23, 2015
MP3-jPlayer [mp3-jplayer] < 2.4 (closed)
unknown
Because of this vulnerability, attackers can download or disclosure file's from the root-path.
Update the plugin.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Mar 23, 2015
MP3-jPlayer <= 1.8.11 - Cross-Site Scripting
medium
The MP3-jPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘mp3’ parameter in versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 1.8.11
- Fixed in:
- 1.8.12
- Disclosed:
- Jan 5, 2015
MP3-jPlayer [mp3-jplayer] < 1.8.12 (closed)
unknown
The MP3-jPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘mp3’ parameter in versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.12
- Disclosed:
- Jan 5, 2015
MP3-jPlayer [mp3-jplayer] < 1.8 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability in jPlayer.swf.
Upgrade this plugin.
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Aug 1, 2014
MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability in jPlayer.swf.
Upgrade this plugin.
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Aug 1, 2014
MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability in jPlayer.swf.
Upgrade this plugin.
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Aug 1, 2014
MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability in jPlayer.swf.
Upgrade this plugin.
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Aug 1, 2014
MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Aug 1, 2014
MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Aug 1, 2014
MP3-jPlayer < 1.8.8 - Cross-Site Scripting
high
The MP3-jPlayer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.1
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Feb 23, 2014
MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)
unknown
The MP3-jPlayer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Feb 23, 2014
MP3-jPlayer [mp3-jplayer] < 2.5 (closed)
unknown
The MP3-jPlayer WordPress plugin was affected by a Local File Disclosure security vulnerability.
- Affected:
- up to 2.5
- Fixed in:
- 2.5
MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)
unknown
The MP3-jPlayer WordPress plugin was affected by a jPlayer.swf Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)
unknown
The MP3-jPlayer WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database