Input validation vulnerability in WordPress RokBox 2.13

The WordPress RokBox plugin, used in versions up to and including 2.13, is vulnerable to Content Spoofing. This means that unauthenticated attackers can make it look like a file is coming from another domain. This is done via the ‘file’, ‘config’, and ‘abouttext’ parameters in the ‘thumb.php’ and ‘jwplayer.swf’ files.

Detected in:

WordPress RokBox open vulnerable versions: >= * <= 2.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.