Vulnerabilities > Videowhisper > Broadcast Live Video > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-23 CVE-2024-12504 Cross-site Scripting vulnerability in Videowhisper Broadcast Live Video
The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
videowhisper CWE-79
5.4