Cross-Site Scripting Vulnerability in VideoWhisper Live Streaming Integration for WordPress
CVE-2014-1906
Currently unrated
Summary
Multiple cross-site scripting (XSS) vulnerabilities exist in the VideoWhisper Live Streaming Integration plugin for WordPress. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML into various parameters, including 'm' in lb_status.php, 'msg' in vc_chatlog.php, and several others across different components like channel.php, htmlchat.php, and video.php. Exploiting these XSS vulnerabilities could lead to unauthorized access and manipulation of user data or web application behavior.
References
Timeline
Vulnerability published
Vulnerability Reserved