cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forradio-player radio-player

Direction: ascending
Jun 07, 2024

Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # 971fb8ca82e479cf299b6fe3febbcab5da5854dc

Date
Feb 28, 2022
Research Description
Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress [radio-player] < 1.0.8 WordPress "Radio Player – Live Shoutcast, Icecast and Audio Stream Player for WordPress" plugin < 1.0.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress "Radio Player – Live Shoutcast, Icecast and Audio Stream Player for WordPress" plugin (versions < 1.0.8).
Affected versions
max 1.0.8.
Status
vulnerable

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-34753

CVE, Research URL

CVE-2024-34753

Date
Jun 11, 2024
Research Description
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
Affected versions
max 2.0.74.
Status
vulnerable

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-32506

CVE, Research URL

CVE-2024-32506

Date
Apr 17, 2024
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
Affected versions
max 2.0.74.
Status
vulnerable

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-33592

CVE, Research URL

CVE-2024-33592

Date
Apr 25, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
Affected versions
max 2.0.74.
Status
vulnerable

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-29811

CVE, Research URL

CVE-2024-29811

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73.
Affected versions
max 2.0.74.
Status
vulnerable

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-2906

CVE, Research URL

CVE-2024-2906

Date
Mar 26, 2024
Research Description
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
Affected versions
max 2.0.74.
Status
vulnerable
Aug 18, 2024

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2023-4024

CVE, Research URL

CVE-2023-4024

Date
Aug 17, 2024
Research Description
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances.
Affected versions
max 2.0.74.
Status
vulnerable

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2023-4027

CVE, Research URL

CVE-2023-4027

Date
Aug 17, 2024
Research Description
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings.
Affected versions
max 2.0.74.
Status
vulnerable

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2023-4025

CVE, Research URL

CVE-2023-4025

Date
Aug 17, 2024
Research Description
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances.
Affected versions
max 2.0.74.
Status
vulnerable
Sep 25, 2024

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-8267

CVE, Research URL

CVE-2024-8267

Date
Sep 25, 2024
Research Description
The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute within the 'wp:radio-player' Gutenberg block in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.0.79.
Status
vulnerable
Nov 14, 2024

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.0.8.
Status
vulnerable
Dec 18, 2024

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-54385

CVE, Research URL

CVE-2024-54385

Date
Dec 16, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through 2.0.82.
Affected versions
max 2.0.82.
Status
vulnerable
Jan 27, 2026

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2026-24548

CVE, Research URL

CVE-2026-24548

Date
Jan 23, 2026
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Prince Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.91.
Affected versions
max 2.0.91.
Status
vulnerable
May 01, 2026

Radio Player &#8211; Live Shoutcast, Icecast and Any Audio Stream Player for WordPress # CVE-2024-13362

CVE, Research URL

CVE-2024-13362

Date
May 01, 2026
Research Description
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 8.0.8.
Status
vulnerable