plugin

Wordtube Vulnerabilities

2 known security issues reported for the Wordtube WordPress plugin. Most recent disclosed May 1, 2007.

2 critical

Running Wordtube on your site? Check whether your installed version is affected.

Scan your site free

wordTube <= 1.43 - Remote File Inclusion

critical

PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

CVSS:
9.8
Affected:
up to 1.43
Fixed in:
1.44
Disclosed:
May 1, 2007

CVE-2007-2481 on NVD →

wordTube <= 1.43 - Directory Traversal and File Inclusion

critical

The wordTube plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.43 via the 'wpPATH' parameter found in the wordtube-button.php file. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This can al...

CVSS:
9.8
Affected:
up to 1.43
Fixed in:
1.44
Disclosed:
May 1, 2007

CVE-2007-2482 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database