WP Video Lightbox

The WordPress Video Lightbox plugin allows users to embed videos on a page using a lightbox overlay display. This plugin supports various media types, including images, flash, YouTube, Vimeo, and iFrame, and can be viewed on iPhone and iPad. To embed a Vimeo video, users can use the shortcode provided in the post or page, replacing the video ID with their own. The plugin also supports private Vimeo videos with the addition of the "p_hash" parameter.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in WP Video Lightbox 1.9.10

    Fixed

    The WP Video Lightbox plugin for WordPress is at risk of being hacked through a method called Stored Cross-Site Scripting. This can happen if the 'width' parameter is not properly checked and protect...

    Read More
  • Input validation vulnerability in WP Video Lightbox 1.9.6

    Fixed

    The WP Video Lightbox for WordPress is not adequately protected against certain malicious attacks. In versions up to 1.9.6

    Read More
  • Input validation vulnerability in WP Video Lightbox 1.9.2

    Fixed

    Read More
  • Input validation vulnerability in WP Video Lightbox 1.9.4

    Fixed

    The WP Video Lightbox plugin for WordPress is not secure in versions up to 1.9.4. An attacker who has access to the administrative side of the plugin could inject malicious web scripts on pages that w...

    Read More
  • Input validation vulnerability in WP Video Lightbox 1.9.5

    Fixed

    The Video Lightbox plugin for WordPress is not secure in versions 1.4 and below. It is possible for people with high-level access to the website to add malicious code. When someone visits a page that...

    Read More
  • Input validation vulnerability in Jquery plugin PrettyPhoto.js (34 plugins affected)

    Fixed

    A security issue has been found in prettyPhoto 3.1.4 and earlier versions. This issue allows someone who is not authorized to inject code into the website

    Read More