Cross-Site Scripting Vulnerability in VideoWhisper Live Streaming Integration for WordPress
CVE-2014-1906

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
6 March 2014

Summary

Multiple cross-site scripting (XSS) vulnerabilities exist in the VideoWhisper Live Streaming Integration plugin for WordPress. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML into various parameters, including 'm' in lb_status.php, 'msg' in vc_chatlog.php, and several others across different components like channel.php, htmlchat.php, and video.php. Exploiting these XSS vulnerabilities could lead to unauthorized access and manipulation of user data or web application behavior.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.