Broadcast Live Video <= 7.2.4 - Unauthenticated Arbitrary File Deletion
critical
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can...
- CVSS:
- 9.1
- Affected:
- up to 7.2.4
- Fixed in:
- 7.2.5
- Disclosed:
- Jul 21, 2026
CVE-2026-57716 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 - Unauthenticated PHP Object Injection
high
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to PHP Object Injection in versions up to 7.1.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable soft...
- CVSS:
- 8.1
- Affected:
- up to 7.1.3
- Fixed in:
- 7.1.3
- Disclosed:
- May 28, 2026
CVE-2026-27053 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 - Authenticated (Admin+) Remote Code Execution
high
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.1.3 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 7.1.3
- Fixed in:
- 7.1.3
- Disclosed:
- May 25, 2026
CVE-2026-24937 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.2.4 - Cross-Site Request Forgery
medium
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unautho...
- CVSS:
- 4.3
- Affected:
- up to 6.2.4
- Fixed in:
- 6.2.5
- Disclosed:
- May 19, 2025
CVE-2025-48255 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.2.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP allows Cross Site Request Forgery. This issue affects Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP: from n/a through 6.2.4.
- Affected:
- up to 6.2.5
- Fixed in:
- 6.2.5
- Disclosed:
- May 19, 2025
CVE-2025-48255 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.2.1
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper VideoWhisper Live Streaming Integration allows Path Traversal. This issue affects VideoWhisper Live Streaming Integration: from n/a through 6.2.
- Affected:
- up to 6.2.1
- Fixed in:
- 6.2.1
- Disclosed:
- Feb 25, 2025
CVE-2025-26753 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.2.1
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper VideoWhisper Live Streaming Integration allows Path Traversal. This issue affects VideoWhisper Live Streaming Integration: from n/a through 6.2.
- Affected:
- up to 6.2.1
- Fixed in:
- 6.2.1
- Disclosed:
- Feb 25, 2025
CVE-2025-26752 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 - Unauthenticated Arbitrary File Deletion
critical
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 6.1.10. This makes it possible for unauthenticated attackers to delete arbitrary files on the ser...
- CVSS:
- 9.1
- Affected:
- up to 6.1.10
- Fixed in:
- 6.2.1
- Disclosed:
- Feb 14, 2025
CVE-2025-26752 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 - Unauthenticated Arbitrary File Read
high
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.10. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 6.1.10
- Fixed in:
- 6.2.1
- Disclosed:
- Feb 14, 2025
CVE-2025-26753 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.1.10
unknown
[en] The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attribut...
- Affected:
- up to 6.1.10
- Fixed in:
- 6.1.10
- Disclosed:
- Jan 23, 2025
CVE-2024-12504 on NVD →
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. T...
- CVSS:
- 6.4
- Affected:
- up to 6.1.9
- Fixed in:
- 6.1.10
- Disclosed:
- Jan 22, 2025
CVE-2024-12504 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 5.5.16
unknown
[en] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15.
- Affected:
- up to 5.5.16
- Fixed in:
- 5.5.16
- Disclosed:
- Apr 3, 2024
CVE-2023-25699 on NVD →
Live Streaming - Broadcast Live Video <= 5.5.15 - Missing Authorization to Unauthenticated Remote Code Execution
critical
The Live Streaming - Broadcast Live Video Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 5.5.15. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.1
- Affected:
- up to 5.5.15
- Fixed in:
- 5.5.16
- Disclosed:
- Feb 20, 2023
CVE-2023-25699 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.10
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906...
- Affected:
- up to 4.29.10
- Fixed in:
- 4.29.10
- Disclosed:
- Mar 19, 2018
CVE-2014-2297 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.7
unknown
This plugin is prone to videowhisper_streaming.php multiple parameter cross site scripting vulnerability.
Update plugin.
- Affected:
- up to 4.29.7
- Fixed in:
- 4.29.7
- Disclosed:
- May 15, 2015
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5
unknown
[en] The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
- Affected:
- up to 4.29.5
- Fixed in:
- 4.29.5
- Disclosed:
- Dec 29, 2014
CVE-2014-1908 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5
unknown
[en] Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins...
- Affected:
- up to 4.29.5
- Fixed in:
- 4.29.5
- Disclosed:
- Dec 29, 2014
CVE-2014-1905 on NVD →
Broadcast Live Video – Live Streaming < 4.27.4 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.
- CVSS:
- 6.1
- Affected:
- up to 4.27.4
- Fixed in:
- 4.27.4
- Disclosed:
- Jul 1, 2014
CVE-2014-4569 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.27.4
unknown
[en] Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.
- Affected:
- up to 4.27.4
- Fixed in:
- 4.27.4
- Disclosed:
- Jul 1, 2014
CVE-2014-4569 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5
unknown
[en] Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp...
- Affected:
- up to 4.29.5
- Fixed in:
- 4.29.5
- Disclosed:
- Mar 6, 2014
CVE-2014-1907 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) html...
- Affected:
- up to 4.29.5
- Fixed in:
- 4.29.5
- Disclosed:
- Mar 6, 2014
CVE-2014-1906 on NVD →
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.27.4 - Arbitrary File Upload
critical
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins/vide...
- CVSS:
- 9.8
- Affected:
- up to 4.27.4
- Fixed in:
- 4.29.5
- Disclosed:
- Feb 27, 2014
CVE-2014-1905 on NVD →
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 - Arbitrary File Read/Deletion
critical
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logo...
- CVSS:
- 9.8
- Affected:
- up to 4.29.5
- Fixed in:
- 4.29.5
- Disclosed:
- Feb 27, 2014
CVE-2014-1907 on NVD →
Broadcast Live Video – Live Streaming < 4.29.5 - Full Path Disclosure
medium
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
- CVSS:
- 5.3
- Affected:
- up to 4.29.5
- Fixed in:
- 4.29.5
- Disclosed:
- Feb 27, 2014
CVE-2014-1908 on NVD →
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.29.6 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906.4.
- CVSS:
- 6.1
- Affected:
- up to 4.29.6
- Fixed in:
- 4.29.9
- Disclosed:
- Feb 26, 2014
CVE-2014-2297 on NVD →
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 - Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat....
- CVSS:
- 7.1
- Affected:
- up to 4.29.5
- Fixed in:
- 4.29.5
- Disclosed:
- Feb 6, 2014
CVE-2014-1906 on NVD →
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.67.17
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter. NOTE: some of these details are obtained f...
- Affected:
- up to 4.67.17
- Fixed in:
- 4.67.17
- Disclosed:
- Sep 9, 2013
CVE-2013-5714 on NVD →
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.25.3 - Reflected Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter.
- CVSS:
- 6.1
- Affected:
- up to 4.25.3
- Fixed in:
- 4.27
- Disclosed:
- Aug 23, 2013
CVE-2013-5714 on NVD →