plugin

Video Synchro Pdf Vulnerabilities

7 known security issues reported for the Video Synchro Pdf WordPress plugin. Most recent disclosed Apr 25, 2022.

1 critical 1 medium

Running Video Synchro Pdf on your site? Check whether your installed version is affected.

Scan your site free

Videos sync PDF [video-synchro-pdf] <= 1.7.4 (unfixed + closed)

unknown

[en] The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

Affected:
up to 1.7.4
Fix:
No patched version reported
Disclosed:
Apr 25, 2022

CVE-2022-1392 on NVD →

Videos sync PDF <= 1.7.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Videos sync PDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privileges to inject arbitrary web scrip...

CVSS:
5.5
Affected:
up to 1.7.4
Fix:
No patched version reported
Disclosed:
Apr 19, 2022

CVE-2022-50949 on NVD →

Videos sync PDF [video-synchro-pdf] <= 1.7.4 (closed)

unknown

Stored Cross-Site Scripting via Cross-Site Request Forgery (CSRF) vulnerability discovered by UnD3sc0n0c1d0 in WordPress Videos sync PDF plugin (versions <= 1.7.4).

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Apr 19, 2022

Videos sync PDF [video-synchro-pdf] <= 1.7.4 (unfixed + closed)

unknown

The Videos sync PDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privileges to inject arbitrary web scrip...

Affected:
up to 1.7.4
Fix:
No patched version reported
Disclosed:
Apr 19, 2022

Videos sync PDF <= 1.7.4 - Unauthenticated Local File Inclusion

critical

The Videos sync PDF plugin for WordPress is vulnerable to Local File Inclusion in versions up to an equal to 1.7.4 via the `p` parameter found in the ~/video-synchro-pdf/reglages/Menu_Plugins/tout.php file.

CVSS:
9.8
Affected:
up to 1.7.4
Fix:
No patched version reported
Disclosed:
Mar 30, 2022

CVE-2022-1392 on NVD →

Videos sync PDF [video-synchro-pdf] <= 1.7.4 (closed)

unknown

Unauthenticated Local File Inclusion (LFI) vulnerability discovered by Hassan Khan Yusufzai (Splint3r7) in WordPress Videos sync PDF plugin (versions <= 1.7.4).

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Mar 30, 2022

Videos sync PDF [video-synchro-pdf] <= 1.7.4 (unfixed + closed)

unknown

The plugin does not have CSRF check in place when editing a video, and does not escape some of its fields, which could allow attackers to make a logged in admin change them and lead to Stored Cross-Site Scripting issues

Affected:
up to 1.7.4
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database