Cross-Site Scripting Vulnerabilities in VideoWhisper Live Streaming Integration Plugin for WordPress
CVE-2013-5714
Currently unrated
What is CVE-2013-5714?
The VideoWhisper Live Streaming Integration plugin for WordPress contains multiple cross-site scripting vulnerabilities in the ls/htmlchat.php file. Attackers can exploit these vulnerabilities to inject arbitrary web scripts or HTML via the 'name' or 'message' parameters. This can potentially lead to unauthorized actions on behalf of the user, making it crucial for site administrators to address these vulnerabilities promptly.