Soundy Background Music <= 3.9 - Cross-Site Scripting
medium
The Soundy Background Music plugin 3.9 and below for WordPress has Cross-Site Scripting via soundy-background-music\templates\front-end.php (war_soundy_preview parameter).
- CVSS:
- 6.1
- Affected:
- up to 3.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 18, 2018
CVE-2018-6002 on NVD →
Soundy Background Music <= 3.1 - Reflected Cross-Site Scripting
medium
The Soundy Background Music plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'war_soundy_audio_volume’ parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...
- CVSS:
- 6.1
- Affected:
- up to 3.1
- Fixed in:
- 3.2
- Disclosed:
- Mar 12, 2016
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database