plugin

Webcam 2Way Videochat Vulnerabilities

6 known security issues reported for the Webcam 2Way Videochat WordPress plugin. Most recent disclosed Aug 16, 2021.

2 medium

Running Webcam 2Way Videochat on your site? Check whether your installed version is affected.

Scan your site free

2Way VideoCalls and Random Chat &#8211; HTML5 Webcam Videochat [webcam-2way-videochat] < 5.2.8

unknown

[en] The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7.

Affected:
up to 5.2.8
Fixed in:
5.2.8
Disclosed:
Aug 16, 2021

CVE-2021-34656 on NVD →

2Way VideoCalls and Random Chat – HTML5 Webcam Videochat <= 5.2.7 - Reflected Cross-Site Scripting

medium

The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7.

CVSS:
6.1
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Aug 13, 2021

CVE-2021-34656 on NVD →

Webcam 2Way Videochat <= 4.41 - Cross-Site Scripting

medium

The Webcam 2Way Videochat plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.41 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 4.41
Fixed in:
4.41.2
Disclosed:
Sep 17, 2014

2Way VideoCalls and Random Chat &#8211; HTML5 Webcam Videochat [webcam-2way-videochat] < 4.42

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 4.42
Fixed in:
4.42
Disclosed:
Sep 17, 2014

2Way VideoCalls and Random Chat &#8211; HTML5 Webcam Videochat [webcam-2way-videochat] < 4.41.2

unknown

The Webcam 2Way Videochat plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.41 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.41.2
Fixed in:
4.41.2
Disclosed:
Sep 17, 2014

2Way VideoCalls and Random Chat &#8211; HTML5 Webcam Videochat [webcam-2way-videochat] < 4.41.2

unknown

The 2Way VideoCalls &ndash; HTML5 Webcam Videochat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 4.41.2
Fixed in:
4.41.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database