plugin

Mp3 Jplayer Vulnerabilities

29 known security issues reported for the Mp3 Jplayer WordPress plugin. Most recent disclosed Aug 6, 2023.

2 high 2 medium

Running Mp3 Jplayer on your site? Check whether your installed version is affected.

Scan your site free

MP3-jPlayer [mp3-jplayer] < 2.3.4 (closed)

unknown

Update the plugin. Larry W. Cashdollar discovered and reported this Full Path Disclosure (FPD) vulnerability in WordPress MP3 jPlayer Plugin. This vulnerability has been fixed in version 2.3.4.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Aug 6, 2023

MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)

unknown

Update the plugin. HauntIT Blog discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit you...

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Aug 1, 2023

MP3-jPlayer [mp3-jplayer] < 1.8 (closed)

unknown

Upgrade this plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Aug 1, 2023

MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)

unknown

Upgrade this plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 1, 2023

MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)

unknown

Upgrade this plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 1, 2023

MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)

unknown

Upgrade this plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests vi...

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 1, 2023

MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)

unknown

Update the plugin. HauntIT Blog discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit you...

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Aug 1, 2023

MP3-jPlayer [mp3-jplayer] < 2.4 (closed)

unknown

Update the plugin. KedAns-Dz discovered and reported this Local File Inclusion vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentiall...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Mar 23, 2023

MP3-jPlayer [mp3-jplayer] < 2.4 (closed)

unknown

Update the plugin. KedAns-Dz discovered and reported this Local File Inclusion vulnerability in WordPress MP3 jPlayer Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentiall...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Mar 23, 2023

MP3 jPlayer <= 2.7.3 - Cross-Site Request Forgery

high

The MP3 jPlayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.3. This is due to missing or incorrect nonce validation on several of its functions. This makes it possible for unauthenticated attackers to execute them, via forged request granted they can trick a si...

CVSS:
8.8
Affected:
up to 2.7.3
Fix:
No patched version reported
Disclosed:
Sep 1, 2022

CVE-2022-36373 on NVD →

MP3-jPlayer [mp3-jplayer] <= 2.7.3 (unfixed + closed)

unknown

[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress.

Affected:
up to 2.7.3
Fix:
No patched version reported
Disclosed:
Sep 1, 2022

CVE-2022-36373 on NVD →

MP3-jPlayer [mp3-jplayer] < 2.5 (unfixed + closed)

unknown

[en] Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2

Affected:
up to 2.5
Fix:
No patched version reported
Disclosed:
Oct 6, 2016

CVE-2015-1000008 on NVD →

MP3-jPlayer [mp3-jplayer] < 2.3.4 (closed)

unknown

Because of this vulnerability, attackers can disclose path information on wordpress sites. Update the plugin.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Aug 6, 2015

MP3-jPlayer <= 2.4.2 - Full Path Disclosure

medium

The MP3-jPlayer plugin for WordPress is vulnerable to Path Disclosure in versions before 2.5.

CVSS:
5.3
Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Jul 12, 2015

CVE-2015-1000008 on NVD →

MP3-jPlayer [mp3-jplayer] < 2.4 (closed)

unknown

Because of this vulnerability, attackers can download or disclosure file's from the root-path. Update the plugin.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Mar 23, 2015

MP3-jPlayer [mp3-jplayer] < 2.4 (closed)

unknown

Because of this vulnerability, attackers can download or disclosure file's from the root-path. Update the plugin.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Mar 23, 2015

MP3-jPlayer <= 1.8.11 - Cross-Site Scripting

medium

The MP3-jPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘mp3’ parameter in versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 1.8.11
Fixed in:
1.8.12
Disclosed:
Jan 5, 2015

MP3-jPlayer [mp3-jplayer] < 1.8.12 (closed)

unknown

The MP3-jPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘mp3’ parameter in versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

Affected:
up to 1.8.12
Fixed in:
1.8.12
Disclosed:
Jan 5, 2015

MP3-jPlayer [mp3-jplayer] < 1.8 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in jPlayer.swf. Upgrade this plugin.

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Aug 1, 2014

MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in jPlayer.swf. Upgrade this plugin.

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 1, 2014

MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in jPlayer.swf. Upgrade this plugin.

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 1, 2014

MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in jPlayer.swf. Upgrade this plugin.

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 1, 2014

MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Aug 1, 2014

MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Aug 1, 2014

MP3-jPlayer < 1.8.8 - Cross-Site Scripting

high

The MP3-jPlayer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.1
Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Feb 23, 2014

MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)

unknown

The MP3-jPlayer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Feb 23, 2014

MP3-jPlayer [mp3-jplayer] < 2.5 (closed)

unknown

The MP3-jPlayer WordPress plugin was affected by a Local File Disclosure security vulnerability.

Affected:
up to 2.5
Fixed in:
2.5

MP3-jPlayer [mp3-jplayer] < 1.8.4 (closed)

unknown

The MP3-jPlayer WordPress plugin was affected by a jPlayer.swf Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.8.4
Fixed in:
1.8.4

MP3-jPlayer [mp3-jplayer] < 1.8.8 (closed)

unknown

The MP3-jPlayer WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.8.8
Fixed in:
1.8.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database