cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsimple-media-directory simple-media-directory

Direction: ascending
Jul 03, 2024

Simple Video Directory # CVE-2024-5811

CVE, Research URL

CVE-2024-5811

Date
Jul 12, 2024
Research Description
The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable
May 19, 2025

Simple Video Directory # CVE-2024-6809

CVE, Research URL

CVE-2024-6809

Date
May 16, 2025
Research Description
The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Affected versions
Min -, max -.
Status
vulnerable