Known Vulnerabilities for JW Player For WordPress by IlGhera
Listed below are 7 of the newest known vulnerabilities associated with "JW Player For WordPress" by "IlGhera".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-96531 json | The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before renderi... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-93512 json | Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-85415 json | The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as ... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-84937 json | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before ... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-14860 json | The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-9125 json | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [pres... | Not Provided | 2026-06-12 | 2026-08-28 |
| CVE-2025-7963 json | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplay... | Not Provided | 2026-09-02 | 2026-09-03 |