Input validation vulnerability in HTML5 Radio Player – WPBakery Page Builder Addon 2.5

A plugin called “HTML5 Radio Player – WPBakery Page Builder Addon” for WordPress has a security issue. This issue, known as Reflected Cross-Site Scripting, affects all versions up to 2.5. It happens because the plugin does not properly clean up the input and output, which means that attackers who are not logged in can add malicious scripts to pages. This can happen if they convince a user to click on a link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.