01642 06 11 11 Arrange Call

Arbitrary Script Injection in HTML5 Video Player with Playlist Plugin for WordPress

CVE-2014-4534 · MEDIUM

CVE-2014-4534

Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter.

Learn more about our Wordpress Pen Testing.