plugin

Wp Miniaudioplayer Vulnerabilities

2 known security issues reported for the Wp Miniaudioplayer WordPress plugin. Most recent disclosed Feb 12, 2016.

1 high 1 medium

Running Wp Miniaudioplayer on your site? Check whether your installed version is affected.

Scan your site free

mb.miniAudioPlayer <= 1.7.6 - Multiple Vulnerabilities

high

WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind...

CVSS:
7.2
Affected:
up to 1.7.6
Fix:
No patched version reported
Disclosed:
Feb 12, 2016

CVE-2016-0796 on NVD →

mb.mb.miniAudioPlayer < 1.4.3 - Cross-Site Scripting

medium

Themb.miniAudioPlayer – an HTML5 audio player for your mp3 files plugin for WordPress is vulnerable to Cross-Site Scripting via the 'volume' and 'width' parameters in versions before 1.3.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts th...

CVSS:
6.1
Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Sep 24, 2013

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database