plugin

Videowhisper Live Streaming Integration Vulnerabilities

28 known security issues reported for the Videowhisper Live Streaming Integration WordPress plugin. Most recent disclosed Jul 21, 2026.

5 critical 4 high 6 medium

Running Videowhisper Live Streaming Integration on your site? Check whether your installed version is affected.

Scan your site free

Broadcast Live Video <= 7.2.4 - Unauthenticated Arbitrary File Deletion

critical

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can...

CVSS:
9.1
Affected:
up to 7.2.4
Fixed in:
7.2.5
Disclosed:
Jul 21, 2026

CVE-2026-57716 on NVD →

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 - Unauthenticated PHP Object Injection

high

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to PHP Object Injection in versions up to 7.1.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable soft...

CVSS:
8.1
Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
May 28, 2026

CVE-2026-27053 on NVD →

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 - Authenticated (Admin+) Remote Code Execution

high

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.1.3 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
May 25, 2026

CVE-2026-24937 on NVD →

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.2.4 - Cross-Site Request Forgery

medium

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unautho...

CVSS:
4.3
Affected:
up to 6.2.4
Fixed in:
6.2.5
Disclosed:
May 19, 2025

CVE-2025-48255 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.2.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP allows Cross Site Request Forgery. This issue affects Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP: from n/a through 6.2.4.

Affected:
up to 6.2.5
Fixed in:
6.2.5
Disclosed:
May 19, 2025

CVE-2025-48255 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.2.1

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper VideoWhisper Live Streaming Integration allows Path Traversal. This issue affects VideoWhisper Live Streaming Integration: from n/a through 6.2.

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Feb 25, 2025

CVE-2025-26753 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.2.1

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper VideoWhisper Live Streaming Integration allows Path Traversal. This issue affects VideoWhisper Live Streaming Integration: from n/a through 6.2.

Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Feb 25, 2025

CVE-2025-26752 on NVD →

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 - Unauthenticated Arbitrary File Deletion

critical

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 6.1.10. This makes it possible for unauthenticated attackers to delete arbitrary files on the ser...

CVSS:
9.1
Affected:
up to 6.1.10
Fixed in:
6.2.1
Disclosed:
Feb 14, 2025

CVE-2025-26752 on NVD →

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 - Unauthenticated Arbitrary File Read

high

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.10. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 6.1.10
Fixed in:
6.2.1
Disclosed:
Feb 14, 2025

CVE-2025-26753 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 6.1.10

unknown

[en] The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attribut...

Affected:
up to 6.1.10
Fixed in:
6.1.10
Disclosed:
Jan 23, 2025

CVE-2024-12504 on NVD →

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. T...

CVSS:
6.4
Affected:
up to 6.1.9
Fixed in:
6.1.10
Disclosed:
Jan 22, 2025

CVE-2024-12504 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 5.5.16

unknown

[en] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15.

Affected:
up to 5.5.16
Fixed in:
5.5.16
Disclosed:
Apr 3, 2024

CVE-2023-25699 on NVD →

Live Streaming - Broadcast Live Video <= 5.5.15 - Missing Authorization to Unauthenticated Remote Code Execution

critical

The Live Streaming - Broadcast Live Video Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 5.5.15. This allows unauthenticated attackers to execute code on the server.

CVSS:
9.1
Affected:
up to 5.5.15
Fixed in:
5.5.16
Disclosed:
Feb 20, 2023

CVE-2023-25699 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.10

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906...

Affected:
up to 4.29.10
Fixed in:
4.29.10
Disclosed:
Mar 19, 2018

CVE-2014-2297 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.7

unknown

This plugin is prone to videowhisper_streaming.php multiple parameter cross site scripting vulnerability. Update plugin.

Affected:
up to 4.29.7
Fixed in:
4.29.7
Disclosed:
May 15, 2015

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5

unknown

[en] The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

Affected:
up to 4.29.5
Fixed in:
4.29.5
Disclosed:
Dec 29, 2014

CVE-2014-1908 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5

unknown

[en] Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins...

Affected:
up to 4.29.5
Fixed in:
4.29.5
Disclosed:
Dec 29, 2014

CVE-2014-1905 on NVD →

Broadcast Live Video – Live Streaming < 4.27.4 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.

CVSS:
6.1
Affected:
up to 4.27.4
Fixed in:
4.27.4
Disclosed:
Jul 1, 2014

CVE-2014-4569 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.27.4

unknown

[en] Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.

Affected:
up to 4.27.4
Fixed in:
4.27.4
Disclosed:
Jul 1, 2014

CVE-2014-4569 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5

unknown

[en] Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp...

Affected:
up to 4.29.5
Fixed in:
4.29.5
Disclosed:
Mar 6, 2014

CVE-2014-1907 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.29.5

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) html...

Affected:
up to 4.29.5
Fixed in:
4.29.5
Disclosed:
Mar 6, 2014

CVE-2014-1906 on NVD →

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.27.4 - Arbitrary File Upload

critical

Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins/vide...

CVSS:
9.8
Affected:
up to 4.27.4
Fixed in:
4.29.5
Disclosed:
Feb 27, 2014

CVE-2014-1905 on NVD →

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 - Arbitrary File Read/Deletion

critical

Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logo...

CVSS:
9.8
Affected:
up to 4.29.5
Fixed in:
4.29.5
Disclosed:
Feb 27, 2014

CVE-2014-1907 on NVD →

Broadcast Live Video – Live Streaming < 4.29.5 - Full Path Disclosure

medium

The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

CVSS:
5.3
Affected:
up to 4.29.5
Fixed in:
4.29.5
Disclosed:
Feb 27, 2014

CVE-2014-1908 on NVD →

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.29.6 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906.4.

CVSS:
6.1
Affected:
up to 4.29.6
Fixed in:
4.29.9
Disclosed:
Feb 26, 2014

CVE-2014-2297 on NVD →

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 - Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat....

CVSS:
7.1
Affected:
up to 4.29.5
Fixed in:
4.29.5
Disclosed:
Feb 6, 2014

CVE-2014-1906 on NVD →

Broadcast Live Video &#8211; Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] < 4.67.17

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter. NOTE: some of these details are obtained f...

Affected:
up to 4.67.17
Fixed in:
4.67.17
Disclosed:
Sep 9, 2013

CVE-2013-5714 on NVD →

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.25.3 - Reflected Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter.

CVSS:
6.1
Affected:
up to 4.25.3
Fixed in:
4.27
Disclosed:
Aug 23, 2013

CVE-2013-5714 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database