CVE-2014-4570: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) roomname parameter to clogin.php or (2) room parameter to index.php in vp/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4570?
CVE-2014-4570 is considered a medium severity vulnerability due to its cross-site scripting (XSS) risks.
How do I fix CVE-2014-4570?
To fix CVE-2014-4570, update the VideoWhisper Video Presentation plugin to version 3.31 or later.
What are the affected versions of VideoWhisper for CVE-2014-4570?
Versions of VideoWhisper Video Presentation prior to 3.31 are affected by CVE-2014-4570.
What are the attack vectors for CVE-2014-4570?
CVE-2014-4570 allows remote attackers to exploit the vulnerability through the room_name parameter in c_login.php or the room parameter in index.php.
What kind of attack can CVE-2014-4570 enable?
CVE-2014-4570 enables attackers to inject arbitrary web scripts or HTML, which can lead to compromised user sessions and data.