ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Flash & HTML5 Video Plugin - Cross Site Request Forgery

Product
JW Player
Description
This Flash & HTML5 Video plugin is prone to a CSRF vulnerability. It allows an attacker to perform certain actions that lead to further attacks.
Solution
Update the plugin.
Classification
Type Cross Site Request Forgery (CSRF)
OWASP Top 10 A8: Cross Site Request Forgery (CSRF)
References
Exploit-DB
CVE
Name CVE-2014-4030
Versions
Affected In <= 2.1.3
Fixed In 2.1.4
Disclosure date
2014-06-10
Credits
Tom Adams