The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/admin.php file which allows unauthenticated attackers to inject arbitrary web scripts in versions up to, and including, 1.7.21.
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2702715%40wp-youtube-live&new=2702715%40wp-youtube-live&sfp_email=&sfph_mail= | Patch Release Notes Vendor Advisory |
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1187 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-04-19 14:15
Updated : 2022-04-27 10:06
NVD link : CVE-2022-1187
Mitre link : CVE-2022-1187
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
wp_youtube_live_project
- wp_youtube_live