Input validation vulnerability in 2Way VideoCalls and Random Chat – HTML5 Webcam Videochat 4.41

The Webcam 2Way Videochat plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Scripting (also known as XSS). This type of attack can occur when the plugin does not properly filter or secure the input of data. This means that, in versions of the plugin up to and including 4.41, an attacker who is not logged in can inject certain web scripts into a victim’s browser which then execute.

Detected in:

2Way VideoCalls and Random Chat – HTML5 Webcam Videochat fixed vulnerable versions: >= * <= 4.41

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.