Executive brief
A code injection vulnerability exists in the VideoWhisper Broadcast Live Video plugin for WordPress, which is used to manage live streaming content. An attacker with administrative privileges can execute malicious code on the server hosting the website. This could lead to a complete takeover of the site, unauthorized access to sensitive data, or the installation of backdoors for persistent access.
Technical details
The VideoWhisper Broadcast Live Video plugin for WordPress contains a code injection vulnerability (CWE-94) in versions prior to 7.1.3. The flaw allows for Remote Code Execution (RCE) by improperly controlling the generation of code within the application. While the attack vector is network-based and has low complexity, it requires high privileges (Administrator level) to exploit. Successful exploitation allows an attacker to execute arbitrary commands on the underlying server, potentially leading to full system compromise. The issue is resolved in version 7.1.3.
Affected products
- VideoWhisper.Com Broadcast Live Video before 7.1.3
Timeline
- 2025-11-25: other: Reported by researcher SSL-6-s0d
- 2026-05-25: patched: Version 7.1.3 released to address the vulnerability
- 2026-05-25: disclosed: Publicly disclosed by Patchstack