Videowhisper develops a suite of WordPress plugins and web-based tools centered on live streaming, video content, and monetization features that extend media and commerce functionality across self-hosted WordPress installations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a tendency to acquire public exploit tooling. The exposure recurs across its streaming integration, webcam recording, gallery, and micropayment products through a consistent pattern of web-layer weakness classes: cross-site scripting, CSRF, code injection, path traversal, and sensitive information disclosure—flaws that reflect the complexity of handling user-generated content, form submissions, and file paths within plugin ecosystems. Defenders should treat Videowhisper plugin updates as priority patches, especially on internet-facing WordPress instances; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Videowhisper over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-1905HIGH Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute a | Dec 29, 2014 | 10.0 | 39 | NO | YES |
CVE-2023-25699CRITICAL Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Comma | Apr 3, 2024 | 9.8 | 30 | NO | NO |
CVE-2014-1907MEDIUM Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files vi | Mar 6, 2014 | 6.4 | 30 | NO | YES |
CVE-2026-57696HIGH Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | Jul 23, 2026 | 7.1 | 29 | NO | NO |
CVE-2015-9272CRITICAL The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are th | Oct 5, 2018 | 9.8 | 26 | NO | NO |
CVE-2015-9271CRITICAL The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file s | Oct 4, 2018 | 9.8 | 25 | NO | NO |
CVE-2014-1908MEDIUM The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress | Dec 29, 2014 | 5.0 | 25 | NO | YES |
CVE-2025-48255HIGH Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Request Forgery.This issue affects Br | May 19, 2025 | 8.8 | 24 | NO | NO |
CVE-2010-4971MEDIUM Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r paramet | Nov 2, 2011 | 4.3 | 24 | NO | YES |
CVE-2022-27629HIGH Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.6 allows a remote unauthenticat | Apr 20, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Videowhisper.
Media articles that mention a CVE ID that affects a product developed by Videowhisper — matched by CVE ID, not by vendor name.