plugin

Soundcloud Is Gold Vulnerabilities

7 known security issues reported for the Soundcloud Is Gold WordPress plugin. Most recent disclosed Dec 13, 2024.

3 medium

Running Soundcloud Is Gold on your site? Check whether your installed version is affected.

Scan your site free

SoundCloud Is Gold [soundcloud-is-gold] <= 2.5.1 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Thomas Michalak Soundcloud Is Gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Soundcloud Is Gold: from n/a through 2.5.1.

Affected:
up to 2.5.1
Fix:
No patched version reported
Disclosed:
Dec 13, 2024

CVE-2023-32586 on NVD →

Soundcloud Is Gold <= 2.5.1 - Missing Authorization to Soundcloud User Add

medium

The Soundcloud Is Gold plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soundcloud_is_gold_add_user() function called via an AJAX action in versions up to, and including, 2.5.1. This makes it possible for authenticated attackers, with subscriber-level acce...

CVSS:
4.3
Affected:
up to 2.5.1
Fix:
No patched version reported
Disclosed:
May 11, 2023

CVE-2023-32586 on NVD →

SoundCloud Is Gold [soundcloud-is-gold] < 2.3.2 (closed)

unknown

[en] The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Sep 26, 2019

CVE-2015-9420 on NVD →

SoundCloud Is Gold [soundcloud-is-gold] < 2.3.2 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Nov 24, 2015

SoundCloud Is Gold <= 2.3.1 - Reflected Cross-Site Scripting

medium

The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.

CVSS:
6.1
Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Aug 26, 2015

CVE-2015-9420 on NVD →

SoundCloud Is Gold [soundcloud-is-gold] < 2.2.1 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter in a soundcloud_is_gold_player_preview action to wp-admin/admin-ajax.php.

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Jan 16, 2014

CVE-2012-6624 on NVD →

Soundcloud Is Gold <= 2.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter in a soundcloud_is_gold_player_preview action to wp-admin/admin-ajax.php.

CVSS:
6.1
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
May 15, 2012

CVE-2012-6624 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database