The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jan 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Videowhisper
Videowhisper broadcast Live Video |
|
CPEs | cpe:2.3:a:videowhisper:broadcast_live_video:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Videowhisper
Videowhisper broadcast Live Video |
Thu, 23 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
Title | Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-23T14:39:57.630Z
Reserved: 2024-12-11T13:09:37.334Z
Link: CVE-2024-12504

Updated: 2025-01-23T14:39:53.565Z

Status : Analyzed
Published: 2025-01-23T12:15:27.610
Modified: 2025-01-31T16:05:27.487
Link: CVE-2024-12504

No data.