Extension WordPress
Vulnérabilités Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player
Cette page rassemble les failles publiées pour Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player
14 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.0.82
2.0.83
30/04/2026
Radio Player <= 2.0.91 – Unauthenticated Server-Side Request Forgery
The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.91. This makes it possible for unauthenticated attackers to make…
*-2.0.91
Non indiqué
23/01/2026
Radio Player <= 2.0.83 – Unauthenticated Server-Side Request Forgery
The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.83. This makes it possible for unauthenticated attackers…
*-2.0.83
2.0.85
12/12/2024
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress <= 2.0.78 – Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute
The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute within the 'wp:radio-player' Gutenberg block in all versions up to, and…
*-2.0.78
2.0.79
23/09/2024
Radio Player <= 2.0.73 – Missing Authorization to Player Update
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to…
*-2.0.73
2.0.74
16/08/2024
Radio Player <= 2.0.73 – Missing Authorization to Player Deletion
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to…
*-2.0.73
2.0.74
16/08/2024
Radio Player <= 2.0.73 – Missing Authorization to Settings Update
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to…
*-2.0.73
2.0.74
16/08/2024
Radio Player <= 2.0.73 – Missing Authorization
The Radio Player plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the render_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to…
*-2.0.73
2.0.74
14/05/2024
Radio Player <= 2.0.73 – Unauthenticated Server-Side Request Forgery
The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers…
*-2.0.73
2.0.74
25/04/2024
Radio Player <= 2.0.73 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.73 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.0.73
2.0.74
25/04/2024
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress <= 2.0.73 – Missing Authorization to Authenticated (Subscriber+) Information Disclosure
The Radio Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.73. This makes it possible for authenticated attackers, with subscriber-level access…
*-2.0.73
2.0.74
15/04/2024
Radio Player <= 2.0.73 – Missing Authorization via get_players
The Radio Player plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_players' function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to…
*-2.0.73
2.0.74
26/03/2024
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.0.2-2.0.4
2.0.5
18/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.0.8)
1.0.8
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.