vendor:
WordPress Video Player
by:
Securify
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: WordPress Video Player
Affected Version From: 1.5.16
Affected Version To: 1.5.18
Patch Exists: YES
Related CWE: None
CPE: a:wordpress:wordpress_video_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Multiple SQL injection vulnerabilities in WordPress Video Player
It was discovered that WordPress Video Player is affected by multiple blind SQL injection vulnerabilities. Using these issues it is possible for a logged on Contributor (or higher) to extract arbitrary data (eg, the Administrator's password hash) from the WordPress database.
Mitigation:
This issue is resolved in WordPress Video Player 1.5.18.