VendorsVideoWhispervideo_presentationall versions
Vulnerabilities

VideoWhisper Video Presentation for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-9272
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
Published 2018-10-05 · Modified
9.8EPSS 0.050
CVE-2014-4570
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/.
Published 2014-07-02 · Modified
4.3EPSS 0.020