Input validation vulnerability in Dewplayer 1.2

The Dewplayer plugin for WordPress is not secure in versions up to 1.2. Attackers can use this flaw to insert malicious web scripts into the plugin, which can then be run in the victim’s browser. To prevent this from happening, it is important to make sure that the plugin is up to date and that input is properly sanitized and output is properly escaped.

Detected in:

Dewplayer open vulnerable versions: >= * <= 1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.