VideoWhisper Video Presentation [videowhisper-video-presentation] < 4.6.1
unknown
[en] The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.1
- Disclosed:
- Oct 5, 2018
CVE-2015-9272 on NVD →
VideoWhisper Video Presentation [videowhisper-video-presentation] < 3.31.18 (closed)
unknown
WordPress Kernel theme is prone to a remote file upload vulnerability. Because of this vulnerability, anyone can upload the files (for the example, .zip, .rar, .mp3, .jpeg, .txt, .html, etc.) to an wordpress site.
Upgrade the plugin.
- Affected:
- up to 3.31.18
- Fixed in:
- 3.31.18
- Disclosed:
- Apr 2, 2015
VideoWhisper Video Presentation <= 4.1.4 - Arbitrary File Upload
critical
The videowhisper-video-presentation plugin 4.1.4 and below for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
- CVSS:
- 9.8
- Affected:
- up to 4.1.4
- Fixed in:
- 4.6.1
- Disclosed:
- Mar 29, 2015
CVE-2015-9272 on NVD →
VideoWhisper Video Presentation [videowhisper-video-presentation] < 3.31.2 (closed)
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/.
- Affected:
- up to 3.31.2
- Fixed in:
- 3.31.2
- Disclosed:
- Jul 2, 2014
CVE-2014-4570 on NVD →
VideoWhisper Video Presentation <= 3.25 - Reflected Cross-Site Scripting
medium
The VideoWhisper Video Presentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'room_name' & 'room' parameters in versions up to, and including, 3.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 3.25
- Fixed in:
- 3.31
- Disclosed:
- Jun 12, 2014
CVE-2014-4570 on NVD →
VideoWhisper Video Presentation [videowhisper-video-presentation] < 3.18 (closed)
unknown
VideoWhisper Video Presentation plugin is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible.
Update...
- Affected:
- up to 3.18
- Fixed in:
- 3.18
- Disclosed:
- Jun 7, 2012
VideoWhisper Video Presentation [videowhisper-video-presentation] < 1.2 (closed)
unknown
VideoWhisper Video Presentation plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Upgrade the plugin.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Sep 2, 2011
VideoWhisper Video Presentation [videowhisper-video-presentation] <= 3.17 (unfixed)
unknown
The VideoWhisper Video Presentation WordPress plugin was affected by a 'vw_upload.php' Arbitrary File Upload security vulnerability.
- Affected:
- up to 3.17
- Fix:
- No patched version reported
VideoWhisper Video Presentation [videowhisper-video-presentation] <= 1.1 (unfixed)
unknown
The VideoWhisper Video Presentation WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 1.1
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database