Vulnerabilities > Videowhisper > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-10-05 | CVE-2015-9272 | Code Injection vulnerability in Videowhisper Video Presentation 3.31.17 The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code. | 7.5 |
2018-10-04 | CVE-2015-9271 | Unrestricted Upload of File with Dangerous Type vulnerability in Videowhisper Video Conference 4.91.8 The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905. | 7.5 |