SpiderVPlayer [player] <= 1.5.22 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebDorado SpiderVPlayer allows Stored XSS.This issue affects SpiderVPlayer: from n/a through 1.5.22.
- Affected:
- up to 1.5.22
- Fix:
- No patched version reported
- Disclosed:
- Nov 30, 2023
CVE-2023-48320 on NVD →
Video Player <= 1.5.22 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The SpiderVPlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...
- CVSS:
- 4.4
- Affected:
- up to 1.5.22
- Fix:
- No patched version reported
- Disclosed:
- Nov 23, 2023
CVE-2023-48320 on NVD →
SpiderVPlayer [player] <= 1.5.22 (unfixed + closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions.
- Affected:
- up to 1.5.22
- Fix:
- No patched version reported
- Disclosed:
- Oct 18, 2023
CVE-2023-45632 on NVD →
Video Player <= 1.5.22 - Reflected Cross-Site Scripting
medium
The Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 1.5.22
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2023
CVE-2023-45632 on NVD →
SpiderVPlayer [player] < 2.2 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability via "get" parameter.
Upgrade the plugin.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Jul 20, 2016
SpiderVPlayer [player] < 1.5.18 (closed)
unknown
This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 1.5.18
- Fixed in:
- 1.5.18
- Disclosed:
- Jul 20, 2016
SpiderVPlayer < 1.5.18 - Multiple Blind Authenticated SQL Injections
high
The SpiderVPlayer plugin for WordPress is vulnerable to Multiple Blind Authenticated SQL Injections via the 'order_by' parameter used in various functions in versions before 1.5.18 due to a lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional...
- CVSS:
- 8.8
- Affected:
- up to 1.5.18
- Fixed in:
- 1.5.18
- Disclosed:
- Jul 19, 2016
SpiderVPlayer [player] < 1.5.18 (closed)
unknown
The SpiderVPlayer plugin for WordPress is vulnerable to Multiple Blind Authenticated SQL Injections via the 'order_by' parameter used in various functions in versions before 1.5.18 due to a lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional...
- Affected:
- up to 1.5.18
- Fixed in:
- 1.5.18
- Disclosed:
- Jul 19, 2016
SpiderVPlayer< 1.5.5 - Reflected Cross-Site Scripting
medium
The SpiderVPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Feb 2, 2015
SpiderVPlayer [player] < 1.5.5 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Feb 2, 2015
SpiderVPlayer [player] < 1.5.5 (closed)
unknown
The SpiderVPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Feb 2, 2015
SpiderVPlayer <= 1.5.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Nov 11, 2014
CVE-2014-8584 on NVD →
SpiderVPlayer [player] < 1.5.2 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Nov 4, 2014
CVE-2014-8584 on NVD →
SpiderVPlayer <= 2.1 - Reflected Cross-Site Scripting
medium
The SpiderVPlayer for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_v_player_id’ parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2013
SpiderVPlayer [player] <= 2.1 (unfixed + closed)
unknown
The SpiderVPlayer for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_v_player_id’ parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2013
SpiderVPlayer [player] <= 2.1 (closed)
unknown
[en] SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- May 10, 2013
CVE-2013-3532 on NVD →
SpiderVPlayer <= 2.1 - SQL Injection
critical
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.
- CVSS:
- 9.8
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 11, 2013
CVE-2013-3532 on NVD →
SpiderVPlayer [player] < 2.2 (closed)
unknown
This WordPress Spider Video Player plugin's "theme" parameter is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Apr 11, 2013
SpiderVPlayer [player] < 1.5.18 (closed)
unknown
The SpiderVPlayer WordPress plugin was affected by a Multiple Authenticated Blind SQL Injection security vulnerability.
- Affected:
- up to 1.5.18
- Fixed in:
- 1.5.18
SpiderVPlayer [player] < 1.5.5 (closed)
unknown
The 'Tags' section of 'WordPress Video Player' under WordPress Administration contains a two fields that are vulnerable to a reflected XSS attack. This is due to the fact that the value passed through to these fields are not encoded prior to output. There is also no nonce on this page, which means t...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
SpiderVPlayer [player] <= 2.1 (unfixed + closed)
unknown
The SpiderVPlayer WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.1
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database