Input validation vulnerability in HLS Player 1.0.10

The plugin called “HLS Player” used in WordPress is not secure. This is because it doesn’t properly check for harmful code and doesn’t protect against it when it is used in the plugin’s ‘hls_player’ feature. This means that someone who has access to the plugin and is logged in as a contributor or higher can add dangerous code to a page, and it will run whenever someone opens that page.

Detected in:

HLS Player fixed vulnerable versions: >= * <= 1.0.10

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.