Extension WordPress

Vulnérabilités Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Cette page rassemble les failles publiées pour Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
4Critiques
14Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

14 fiches

CVE-2026-27053 Élevée · 8,1
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 – Unauthenticated PHP Object Injection

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to PHP Object Injection in versions up to 7.1.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 7.1.3)

Correctif

7.1.3

Publication

28/05/2026

CVE-2026-24937 Élevée · 7,2
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 – Authenticated (Admin+) Remote Code Execution

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.1.3 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access…

Versions affectées

[*, 7.1.3)

Correctif

7.1.3

Publication

25/05/2026

CVE-2025-48255 Moyenne · 4,3
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.2.4 – Cross-Site Request Forgery

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.4. This is due to missing or incorrect nonce validation…

Versions affectées

*-6.2.4

Correctif

6.2.5

Publication

19/05/2025

CVE-2025-26752 Critique · 9,1
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 – Unauthenticated Arbitrary File Deletion

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 6.1.10.…

Versions affectées

*-6.1.10

Correctif

6.2.1

Publication

14/02/2025

CVE-2025-26753 Élevée · 7,5
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 – Unauthenticated Arbitrary File Read

The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.10. This makes it possible for unauthenticated attackers to read the…

Versions affectées

*-6.1.10

Correctif

6.2.1

Publication

14/02/2025

CVE-2024-12504 Moyenne · 6,4
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 6.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient…

Versions affectées

*-6.1.9

Correctif

6.1.10

Publication

22/01/2025

CVE-2023-25699 Critique · 9,1
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Live Streaming – Broadcast Live Video <= 5.5.15 – Missing Authorization to Unauthenticated Remote Code Execution

The Live Streaming – Broadcast Live Video Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 5.5.15. This allows unauthenticated attackers to execute code on the server.

Versions affectées

*-5.5.15

Correctif

5.5.16

Publication

20/02/2023

CVE-2014-4569 Moyenne · 6,1
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming < 4.27.4 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.

Versions affectées

[*, 4.27.4)

Correctif

4.27.4

Publication

01/07/2014

CVE-2014-1905 Critique · 9,8
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.27.4 – Arbitrary File Upload

Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file…

Versions affectées

*-4.27.4

Correctif

4.29.5

Publication

27/02/2014

CVE-2014-1907 Critique · 9,8
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 – Arbitrary File Read/Deletion

Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary…

Versions affectées

[*, 4.29.5)

Correctif

4.29.5

Publication

27/02/2014

CVE-2014-1908 Moyenne · 5,3
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming < 4.29.5 – Full Path Disclosure

The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path…

Versions affectées

[*, 4.29.5)

Correctif

4.29.5

Publication

27/02/2014

CVE-2014-2297 Moyenne · 6,1
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.29.6 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php.…

Versions affectées

*-4.29.6

Correctif

4.29.9

Publication

26/02/2014

CVE-2014-1906 Élevée · 7,1
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php;…

Versions affectées

[*, 4.29.5)

Correctif

4.29.5

Publication

06/02/2014

CVE-2013-5714 Moyenne · 6,1
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.25.3 – Reflected Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter.

Versions affectées

*-4.25.3

Correctif

4.27

Publication

23/08/2013

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités