Webcam Video Conference [videowhisper-video-conference-integration] < 1.1
unknown
Update plugin.
IeDb discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Video Conference Integration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visi...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 5, 2023
Webcam Video Conference [videowhisper-video-conference-integration] < 4.91.9
unknown
Upgrade plugin.
Larry W. Cashdollar discovered and reported this Arbitrary File Upload vulnerability in WordPress Video Conference Integration Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website....
- Affected:
- up to 4.91.9
- Fixed in:
- 4.91.9
- Disclosed:
- May 15, 2023
Webcam Video Conference [videowhisper-video-conference-integration] < 4.52
unknown
Update plugin.
Sammy FORGIT discovered and reported this Arbitrary File Upload vulnerability in WordPress Video Conference Integration Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vu...
- Affected:
- up to 4.52
- Fixed in:
- 4.52
- Disclosed:
- May 15, 2023
Webcam Video Conference [videowhisper-video-conference-integration] < 4.91.9
unknown
[en] The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-...
- Affected:
- up to 4.91.9
- Fixed in:
- 4.91.9
- Disclosed:
- Oct 4, 2018
CVE-2015-9271 on NVD →
Webcam Video Conference [videowhisper-video-conference-integration] < 1.1 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 5, 2015
Webcam Video Conference [videowhisper-video-conference-integration] < 4.91.9 (closed)
unknown
./videowhisper-video-conference-integration/vc/vw_upload.php allows various remote unauthenticated file uploads. Anyone can upload the following files to an unsuspecting wordpress site.
Upgrade plugin.
- Affected:
- up to 4.91.9
- Fixed in:
- 4.91.9
- Disclosed:
- May 15, 2015
Webcam Video Conference [videowhisper-video-conference-integration] < 4.52 (closed)
unknown
This plugin is prone to an arbitrary file upload vulnerability.
Update plugin.
- Affected:
- up to 4.52
- Fixed in:
- 4.52
- Disclosed:
- May 15, 2015
Webcam Video Conference <= 4.91.8 - Unrestricted File Upload leading to Remote Code Execuction
critical
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-...
- CVSS:
- 9.8
- Affected:
- up to 4.91.8
- Fixed in:
- 4.91.9
- Disclosed:
- Mar 29, 2015
CVE-2015-9271 on NVD →
Webcam Video Conference <= 3.1 - Cross-Site Scripting
medium
The Webcam Video Conference plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.1
- Fixed in:
- 4.51
- Disclosed:
- Aug 23, 2013
Webcam Video Conference [videowhisper-video-conference-integration] < 4.51
unknown
The Webcam Video Conference plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 4.51
- Fixed in:
- 4.51
- Disclosed:
- Aug 23, 2013
Webcam Video Conference < 4.51 - Arbitrary File Upload
critical
The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the vw_upload.php file in versions before 4.51. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 4.51
- Fixed in:
- 4.51
- Disclosed:
- Jun 12, 2012
Webcam Video Conference [videowhisper-video-conference-integration] < 4.51
unknown
The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the vw_upload.php file in versions before 4.51. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected:
- up to 4.51
- Fixed in:
- 4.51
- Disclosed:
- Jun 12, 2012
Webcam Video Conference [videowhisper-video-conference-integration] < 4.51
unknown
The Webcam Video Conference WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 4.51
- Fixed in:
- 4.51
Webcam Video Conference [videowhisper-video-conference-integration] <= 4.51 (unfixed)
unknown
The Webcam Video Conference WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 4.51
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database