Description
WordPress Plugin HTML5 MP3 Player with Playlist Free is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin HTML5 MP3 Player with Playlist Free version 2.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7 or latest
References
http://h4x0resec.blogspot.ro/2014/11/wordpress-html5-mp3-player-with.html
http://packetstormsecurity.com/files/129286/WordPress-Html5-Mp3-Player-Full-Path-Disclosure.html
Related Vulnerabilities
Joomla CVE-2026-48902 Vulnerability (CVE-2026-48902)
WordPress Plugin BuddyPress Arbitrary File Deletion (2.7.3)
Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-6188)
Dot CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-37033)
WordPress Plugin WooCommerce Smart Coupons Security Bypass (4.6.0)