plugin

Wonderplugin Audio Vulnerabilities

2 known security issues reported for the Wonderplugin Audio WordPress plugin. Most recent disclosed Feb 19, 2015.

2 high

Running Wonderplugin Audio on your site? Check whether your installed version is affected.

Scan your site free

WonderPlugin Audio Player <= 2.0 - Blind SQL Injection

high

Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL...

CVSS:
8.8
Affected:
up to 2.0
Fixed in:
2.1
Disclosed:
Feb 19, 2015

CVE-2015-2199 on NVD →

WonderPlugin Audio Player < 2.1 - Multiple Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) item[name] or (2) item[customcss] parameter in a wonderplugin_audio_sa...

CVSS:
7.1
Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Feb 19, 2015

CVE-2015-2218 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database