plugin

Wp Rokbox Vulnerabilities

7 known security issues reported for the Wp Rokbox WordPress plugin. Most recent disclosed Dec 17, 2012.

2 critical 2 high 3 medium

Running Wp Rokbox on your site? Check whether your installed version is affected.

Scan your site free

WordPress RokBox <= 2.13 - Arbitrary File Upload

critical

The WordPress RokBox plugin is vulnerable to arbitrary file uploads due to missing file type validation in the 'src' parameter in the 'thumb.php' file in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remot...

CVSS:
9.8
Affected:
up to 2.13
Fix:
No patched version reported
Disclosed:
Dec 17, 2012

WordPress RokBox <= 2.13 - Content Spoofing

critical

The WordPress RokBox plugin is vulnerable to Content Spoofing via the 'file', 'config', and 'abouttext' parameters in the 'thumb.php' and 'jwplayer.swf' files in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to spoof files from other domains.

CVSS:
9.1
Affected:
up to 2.13
Fix:
No patched version reported
Disclosed:
Dec 17, 2012

WordPress RokBox <= 2.13 - Full Path Disclosure

high

The WordPress RokBox plugin is vulnerable to Full Path Disclosure in versions up to, and including, 2.13 via the 'rokbox.php' and 'thumb.php' files. This can allow unauthenticated attackers to extract full paths to otherwise restricted files.

CVSS:
7.5
Affected:
up to 2.13
Fix:
No patched version reported
Disclosed:
Dec 17, 2012

WordPress RokBox <= 2.13 - Denial of Service

high

The WordPress RokBox plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to slow the response time of the vulnerable service to an unusable speed and/or completely deny it.

CVSS:
7.5
Affected:
up to 2.13
Fix:
No patched version reported
Disclosed:
Dec 17, 2012

WordPress RokBox <= 2.13 - Cross-Site Scripting

medium

The WordPress RokBox plugin is vulnerable to Cross-Site Scripting via the 'src' and 'abouttext' parameters in the 'thumb.php' and 'jwplayer.swf' files in versions up to, and including, 2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
6.1
Affected:
up to 2.13
Fix:
No patched version reported
Disclosed:
Dec 17, 2012

WordPress RokBox <= 2.13 - Sensitive Data Disclosure

medium

The WordPress RokBox plugin is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.13 via the error_log. This can allow unauthenticated attackers to extract sensitive data including error logs which may disclose full paths.

CVSS:
5.3
Affected:
up to 2.13
Fix:
No patched version reported
Disclosed:
Dec 17, 2012

WordPress RokBox <= 2.13 - Abuse of Functionality

medium

The WordPress RokBox plugin is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 2.13. This makes it possible for unauthenticated attackers to use implemented functions for unintended/malicious reasons.

CVSS:
5.3
Affected:
up to 2.13
Fix:
No patched version reported
Disclosed:
Dec 17, 2012

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database