CVE-2026-24937: WordPress Broadcast Live Video plugin < 7.1.3 - Remote Code Execution (RCE) vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection.
This issue affects Broadcast Live Video: from n/a before 7.1.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Broadcast Live Video pluginto a version that resolves this vulnerability.Fixed in 7.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24937?
The severity of CVE-2026-24937 is rated as high with a score of 7.2.
What is CVE-2026-24937 about?
CVE-2026-24937 is a remote code execution vulnerability in the WordPress Broadcast Live Video plugin that allows code injection.
How do I fix CVE-2026-24937?
To fix CVE-2026-24937, update the WordPress Broadcast Live Video plugin to at least version 7.1.3.
What software does CVE-2026-24937 affect?
CVE-2026-24937 affects the VideoWhisper Broadcast Live Video plugin for WordPress.
When was CVE-2026-24937 published?
CVE-2026-24937 was published on May 25, 2026.