Input validation vulnerability in Hermit 音乐播放器 3.1.6

Mufeng’s Hermit 音乐播放器 is a plugin for WordPress websites. Versions of the plugin released before 3.1.6 have a security vulnerability which can be exploited by an attacker. This vulnerability involves Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS). This means that an attacker can use a special type of malicious code (CSRF) to gain access to the website and then store malicious code (XSS) in the title parameter (part of the website where titles are stored).

Detected in:

Hermit 音乐播放器 open vulnerable versions: >= * <= 3.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.