plugin

Player Vulnerabilities

21 known security issues reported for the Player WordPress plugin. Most recent disclosed Nov 30, 2023.

1 critical 1 high 5 medium

Running Player on your site? Check whether your installed version is affected.

Scan your site free

SpiderVPlayer [player] <= 1.5.22 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebDorado SpiderVPlayer allows Stored XSS.This issue affects SpiderVPlayer: from n/a through 1.5.22.

Affected:
up to 1.5.22
Fix:
No patched version reported
Disclosed:
Nov 30, 2023

CVE-2023-48320 on NVD →

Video Player <= 1.5.22 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The SpiderVPlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...

CVSS:
4.4
Affected:
up to 1.5.22
Fix:
No patched version reported
Disclosed:
Nov 23, 2023

CVE-2023-48320 on NVD →

SpiderVPlayer [player] <= 1.5.22 (unfixed + closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions.

Affected:
up to 1.5.22
Fix:
No patched version reported
Disclosed:
Oct 18, 2023

CVE-2023-45632 on NVD →

Video Player <= 1.5.22 - Reflected Cross-Site Scripting

medium

The Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 1.5.22
Fix:
No patched version reported
Disclosed:
Oct 11, 2023

CVE-2023-45632 on NVD →

SpiderVPlayer [player] < 2.2 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability via "get" parameter. Upgrade the plugin.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Jul 20, 2016

SpiderVPlayer [player] < 1.5.18 (closed)

unknown

This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 1.5.18
Fixed in:
1.5.18
Disclosed:
Jul 20, 2016

SpiderVPlayer < 1.5.18 - Multiple Blind Authenticated SQL Injections

high

The SpiderVPlayer plugin for WordPress is vulnerable to Multiple Blind Authenticated SQL Injections via the 'order_by' parameter used in various functions in versions before 1.5.18 due to a lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional...

CVSS:
8.8
Affected:
up to 1.5.18
Fixed in:
1.5.18
Disclosed:
Jul 19, 2016

SpiderVPlayer [player] < 1.5.18 (closed)

unknown

The SpiderVPlayer plugin for WordPress is vulnerable to Multiple Blind Authenticated SQL Injections via the 'order_by' parameter used in various functions in versions before 1.5.18 due to a lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional...

Affected:
up to 1.5.18
Fixed in:
1.5.18
Disclosed:
Jul 19, 2016

SpiderVPlayer< 1.5.5 - Reflected Cross-Site Scripting

medium

The SpiderVPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Feb 2, 2015

SpiderVPlayer [player] < 1.5.5 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Feb 2, 2015

SpiderVPlayer [player] < 1.5.5 (closed)

unknown

The SpiderVPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Feb 2, 2015

SpiderVPlayer <= 1.5.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Nov 11, 2014

CVE-2014-8584 on NVD →

SpiderVPlayer [player] < 1.5.2 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Nov 4, 2014

CVE-2014-8584 on NVD →

SpiderVPlayer <= 2.1 - Reflected Cross-Site Scripting

medium

The SpiderVPlayer for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_v_player_id’ parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Dec 9, 2013

SpiderVPlayer [player] <= 2.1 (unfixed + closed)

unknown

The SpiderVPlayer for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_v_player_id’ parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Dec 9, 2013

SpiderVPlayer [player] <= 2.1 (closed)

unknown

[en] SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
May 10, 2013

CVE-2013-3532 on NVD →

SpiderVPlayer <= 2.1 - SQL Injection

critical

SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.

CVSS:
9.8
Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Apr 11, 2013

CVE-2013-3532 on NVD →

SpiderVPlayer [player] < 2.2 (closed)

unknown

This WordPress Spider Video Player plugin's "theme" parameter is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Apr 11, 2013

SpiderVPlayer [player] < 1.5.18 (closed)

unknown

The SpiderVPlayer WordPress plugin was affected by a Multiple Authenticated Blind SQL Injection security vulnerability.

Affected:
up to 1.5.18
Fixed in:
1.5.18

SpiderVPlayer [player] < 1.5.5 (closed)

unknown

The &#039;Tags&#039; section of &#039;WordPress Video Player&#039; under WordPress Administration contains a two fields that are vulnerable to a reflected XSS attack. This is due to the fact that the value passed through to these fields are not encoded prior to output. There is also no nonce on this page, which means t...

Affected:
up to 1.5.5
Fixed in:
1.5.5

SpiderVPlayer [player] <= 2.1 (unfixed + closed)

unknown

The SpiderVPlayer WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database