mb.miniAudioPlayer <= 1.7.6 - Multiple Vulnerabilities
high
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind...
- CVSS:
- 7.2
- Affected:
- up to 1.7.6
- Fix:
- No patched version reported
- Disclosed:
- Feb 12, 2016
CVE-2016-0796 on NVD →
mb.mb.miniAudioPlayer < 1.4.3 - Cross-Site Scripting
medium
Themb.miniAudioPlayer – an HTML5 audio player for your mp3 files plugin for WordPress is vulnerable to Cross-Site Scripting via the 'volume' and 'width' parameters in versions before 1.3.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts th...
- CVSS:
- 6.1
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Sep 24, 2013
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database