First published: Mon Sep 09 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VideoWhisper Live Streaming Integration | <=4.25.3 | |
VideoWhisper Live Streaming Integration | =1.0.2 | |
VideoWhisper Live Streaming Integration | =2.0 | |
VideoWhisper Live Streaming Integration | =2.1 | |
VideoWhisper Live Streaming Integration | =2.2 | |
VideoWhisper Live Streaming Integration | =4.05 | |
VideoWhisper Live Streaming Integration | =4.07 | |
VideoWhisper Live Streaming Integration | =4.25 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5714 is considered a medium severity vulnerability due to its potential to allow remote attackers to perform cross-site scripting (XSS) attacks on affected sites.
To fix CVE-2013-5714, upgrade the VideoWhisper Live Streaming Integration plugin to the latest version that addresses the XSS vulnerabilities.
CVE-2013-5714 affects VideoWhisper Live Streaming Integration versions up to 4.25.3 and possibly earlier versions.
CVE-2013-5714 can be exploited through the 'name' or 'message' parameters in ls/htmlchat.php, allowing attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2013-5714 is a known vulnerability affecting the VideoWhisper Live Streaming Integration plugin that integrates with WordPress.