plugin

S3 Video Vulnerabilities

10 known security issues reported for the S3 Video WordPress plugin. Most recent disclosed Oct 10, 2016.

4 medium

Running S3 Video on your site? Check whether your installed version is affected.

Scan your site free

S3 Video Plugin [s3-video] <= 0.983 (closed)

unknown

[en] Reflected XSS in wordpress plugin s3-video v0.983

Affected:
up to 0.983
Fixed in:
0.983
Disclosed:
Oct 10, 2016

CVE-2016-1000148 on NVD →

S3 Video <= 0.983 - Reflected Cross-Site Scripting

medium

The S3 Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media' parameter in versions up to, and including, 0.983 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

CVSS:
6.1
Affected:
up to 0.983
Fix:
No patched version reported
Disclosed:
Apr 12, 2016

CVE-2016-1000148 on NVD →

S3 Video Plugin [s3-video] < 0.98 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 0.98
Fixed in:
0.98
Disclosed:
May 15, 2015

VideoJS (Various Versions) - Cross-Site Scripting

medium

The S3 Video, EasySqueezePage, External "Video for Everybody", Videopack, and 1player plugins for WordPress are vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of VideoJS in various versions due to insufficient input sanitization and output escaping. This makes it possible for unau...

CVSS:
6.1
Affected:
up to 0.98
Fixed in:
0.98
Disclosed:
May 14, 2015

S3 Video Plugin [s3-video] < 0.983 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in views/video-management/preview_video.php in the S3 Video plugin before 0.983 for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter.

Affected:
up to 0.983
Fixed in:
0.983
Disclosed:
Jan 8, 2014

CVE-2013-7279 on NVD →

S3 Video <= 0.982 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in views/video-management/preview_video.php in the S3 Video plugin before 0.983 for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter.

CVSS:
6.1
Affected:
up to 0.982
Fixed in:
0.983
Disclosed:
Dec 17, 2013

CVE-2013-7279 on NVD →

S3 Video Plugin < 0.98 - Cross-Site Scripting

medium

The S3 Video Plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.98 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 0.98
Fixed in:
0.98
Disclosed:
May 15, 2013

S3 Video Plugin [s3-video] < 0.98

unknown

The S3 Video Plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.98 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 0.98
Fixed in:
0.98
Disclosed:
May 15, 2013

S3 Video Plugin [s3-video] <= 0.97 (closed)

unknown
Affected:
up to 0.97
Fixed in:
0.97

S3 Video Plugin [s3-video] < 0.98 (closed)

unknown

The s3-video WordPress plugin was affected by a VideoJS Cross Site Scripting security vulnerability.

Affected:
up to 0.98
Fixed in:
0.98

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database