Show filters
2,221 Total Results
Displaying 71-80 of 2,221
Sort by:
Attacker Value
Unknown
CVE-2023-4027
Disclosure Date: August 17, 2024 (last updated September 13, 2024)
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings.
0
Attacker Value
Unknown
CVE-2023-4025
Disclosure Date: August 17, 2024 (last updated August 29, 2024)
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances.
0
Attacker Value
Unknown
CVE-2023-4024
Disclosure Date: August 17, 2024 (last updated August 29, 2024)
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances.
0
Attacker Value
Unknown
CVE-2024-37445
Disclosure Date: July 22, 2024 (last updated July 27, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23.
0
Attacker Value
Unknown
CVE-2024-37957
Disclosure Date: July 20, 2024 (last updated August 31, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bradmax Bradmax Player allows Stored XSS.This issue affects Bradmax Player: from n/a through 1.1.27.
0
Attacker Value
Unknown
CVE-2024-6338
Disclosure Date: July 19, 2024 (last updated July 20, 2024)
The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-5664
Disclosure Date: July 10, 2024 (last updated July 31, 2024)
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-5522
Disclosure Date: June 20, 2024 (last updated June 20, 2024)
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
0
Attacker Value
Unknown
CVE-2024-34753
Disclosure Date: June 11, 2024 (last updated August 08, 2024)
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
0
Attacker Value
Unknown
CVE-2024-35710
Disclosure Date: June 08, 2024 (last updated June 09, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/a through 5.7.3.
0