WonderPlugin Audio Player <= 2.0 - Blind SQL Injection
high
Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL...
- CVSS:
- 8.8
- Affected:
- up to 2.0
- Fixed in:
- 2.1
- Disclosed:
- Feb 19, 2015
CVE-2015-2199 on NVD →
WonderPlugin Audio Player < 2.1 - Multiple Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) item[name] or (2) item[customcss] parameter in a wonderplugin_audio_sa...
- CVSS:
- 7.1
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Feb 19, 2015
CVE-2015-2218 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database