Input validation vulnerability in Dewplayer *

The WordPress Dewplayer and Advanced Dewplayer plugins versions 1.2 and below, respectively, are vulnerable to content spoofing or injection. This means that if an attacker can successfully convince someone to click on a link, they can inject malicious content into legitimate content because the plugins do not properly sanitize the data from their ‘mp3’, ‘file’, ‘sound’, and ‘son’ parameters.

Detected in:

Advanced Dewplayer open vulnerable versions: >= * < 1.5
Dewplayer open vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.