plugin

Videowhisper Video Conference Integration Vulnerabilities

14 known security issues reported for the Videowhisper Video Conference Integration WordPress plugin. Most recent disclosed Jul 5, 2023.

2 critical 1 medium

Running Videowhisper Video Conference Integration on your site? Check whether your installed version is affected.

Scan your site free

Webcam Video Conference [videowhisper-video-conference-integration] < 1.1

unknown

Update plugin. IeDb discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Video Conference Integration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visi...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 5, 2023

Webcam Video Conference [videowhisper-video-conference-integration] < 4.91.9

unknown

Upgrade plugin. Larry W. Cashdollar discovered and reported this Arbitrary File Upload vulnerability in WordPress Video Conference Integration Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website....

Affected:
up to 4.91.9
Fixed in:
4.91.9
Disclosed:
May 15, 2023

Webcam Video Conference [videowhisper-video-conference-integration] < 4.52

unknown

Update plugin. Sammy FORGIT discovered and reported this Arbitrary File Upload vulnerability in WordPress Video Conference Integration Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vu...

Affected:
up to 4.52
Fixed in:
4.52
Disclosed:
May 15, 2023

Webcam Video Conference [videowhisper-video-conference-integration] < 4.91.9

unknown

[en] The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-...

Affected:
up to 4.91.9
Fixed in:
4.91.9
Disclosed:
Oct 4, 2018

CVE-2015-9271 on NVD →

Webcam Video Conference [videowhisper-video-conference-integration] < 1.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 5, 2015

Webcam Video Conference [videowhisper-video-conference-integration] < 4.91.9 (closed)

unknown

./videowhisper-video-conference-integration/vc/vw_upload.php allows various remote unauthenticated file uploads. Anyone can upload the following files to an unsuspecting wordpress site. Upgrade plugin.

Affected:
up to 4.91.9
Fixed in:
4.91.9
Disclosed:
May 15, 2015

Webcam Video Conference [videowhisper-video-conference-integration] < 4.52 (closed)

unknown

This plugin is prone to an arbitrary file upload vulnerability. Update plugin.

Affected:
up to 4.52
Fixed in:
4.52
Disclosed:
May 15, 2015

Webcam Video Conference <= 4.91.8 - Unrestricted File Upload leading to Remote Code Execuction

critical

The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-...

CVSS:
9.8
Affected:
up to 4.91.8
Fixed in:
4.91.9
Disclosed:
Mar 29, 2015

CVE-2015-9271 on NVD →

Webcam Video Conference <= 3.1 - Cross-Site Scripting

medium

The Webcam Video Conference plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 3.1
Fixed in:
4.51
Disclosed:
Aug 23, 2013

Webcam Video Conference [videowhisper-video-conference-integration] < 4.51

unknown

The Webcam Video Conference plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.51
Fixed in:
4.51
Disclosed:
Aug 23, 2013

Webcam Video Conference < 4.51 - Arbitrary File Upload

critical

The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the vw_upload.php file in versions before 4.51. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 4.51
Fixed in:
4.51
Disclosed:
Jun 12, 2012

Webcam Video Conference [videowhisper-video-conference-integration] < 4.51

unknown

The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the vw_upload.php file in versions before 4.51. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Affected:
up to 4.51
Fixed in:
4.51
Disclosed:
Jun 12, 2012

Webcam Video Conference [videowhisper-video-conference-integration] < 4.51

unknown

The Webcam Video Conference WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 4.51
Fixed in:
4.51

Webcam Video Conference [videowhisper-video-conference-integration] <= 4.51 (unfixed)

unknown

The Webcam Video Conference WordPress plugin was affected by an Arbitrary File Upload security vulnerability.

Affected:
up to 4.51
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database