plugin

Videowhisper Video Presentation Vulnerabilities

9 known security issues reported for the Videowhisper Video Presentation WordPress plugin. Most recent disclosed Oct 5, 2018.

1 critical 1 medium

Running Videowhisper Video Presentation on your site? Check whether your installed version is affected.

Scan your site free

VideoWhisper Video Presentation [videowhisper-video-presentation] < 4.6.1

unknown

[en] The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Oct 5, 2018

CVE-2015-9272 on NVD →

VideoWhisper Video Presentation [videowhisper-video-presentation] < 3.31.18 (closed)

unknown

WordPress Kernel theme is prone to a remote file upload vulnerability. Because of this vulnerability, anyone can upload the files (for the example, .zip, .rar, .mp3, .jpeg, .txt, .html, etc.) to an wordpress site. Upgrade the plugin.

Affected:
up to 3.31.18
Fixed in:
3.31.18
Disclosed:
Apr 2, 2015

VideoWhisper Video Presentation <= 4.1.4 - Arbitrary File Upload

critical

The videowhisper-video-presentation plugin 4.1.4 and below for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.

CVSS:
9.8
Affected:
up to 4.1.4
Fixed in:
4.6.1
Disclosed:
Mar 29, 2015

CVE-2015-9272 on NVD →

VideoWhisper Video Presentation [videowhisper-video-presentation] < 3.31.2 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/.

Affected:
up to 3.31.2
Fixed in:
3.31.2
Disclosed:
Jul 2, 2014

CVE-2014-4570 on NVD →

VideoWhisper Video Presentation <= 3.25 - Reflected Cross-Site Scripting

medium

The VideoWhisper Video Presentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'room_name' & 'room' parameters in versions up to, and including, 3.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 3.25
Fixed in:
3.31
Disclosed:
Jun 12, 2014

CVE-2014-4570 on NVD →

VideoWhisper Video Presentation [videowhisper-video-presentation] < 3.18 (closed)

unknown

VideoWhisper Video Presentation plugin is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible. Update...

Affected:
up to 3.18
Fixed in:
3.18
Disclosed:
Jun 7, 2012

VideoWhisper Video Presentation [videowhisper-video-presentation] < 1.2 (closed)

unknown

VideoWhisper Video Presentation plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Sep 2, 2011

VideoWhisper Video Presentation [videowhisper-video-presentation] <= 3.17 (unfixed)

unknown

The VideoWhisper Video Presentation WordPress plugin was affected by a &#039;vw_upload.php&#039; Arbitrary File Upload security vulnerability.

Affected:
up to 3.17
Fix:
No patched version reported

VideoWhisper Video Presentation [videowhisper-video-presentation] <= 1.1 (unfixed)

unknown

The VideoWhisper Video Presentation WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 1.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database