CVE-2014-2297: Videowhisper Live Streaming Integration

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906.4.

Affected products

  • Videowhisper Videowhisper Live Streaming Integration: version 4.29.6 only

Published 2018-03-19. Last modified 2026-06-17.