CVE-2013-5714: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5714?
CVE-2013-5714 is considered a medium severity vulnerability due to its potential to allow remote attackers to perform cross-site scripting (XSS) attacks on affected sites.
How do I fix CVE-2013-5714?
To fix CVE-2013-5714, upgrade the VideoWhisper Live Streaming Integration plugin to the latest version that addresses the XSS vulnerabilities.
Which versions of VideoWhisper Live Streaming Integration are affected by CVE-2013-5714?
CVE-2013-5714 affects VideoWhisper Live Streaming Integration versions up to 4.25.3 and possibly earlier versions.
What are the exploitation vectors for CVE-2013-5714?
CVE-2013-5714 can be exploited through the 'name' or 'message' parameters in ls/htmlchat.php, allowing attackers to inject arbitrary web scripts or HTML.
Is CVE-2013-5714 a known vulnerability in WordPress?
Yes, CVE-2013-5714 is a known vulnerability affecting the VideoWhisper Live Streaming Integration plugin that integrates with WordPress.