web-cam
web-cam has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for web-cam has a vendor fix available, so running the current release closes it.
All of these findings were reported by Gilang - DJ. web-cam is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-6540web-cam <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via slug Parameter
Read the full analysisVulnerability Records
web-cam
Author
murtuzamakda52
To use this plugin, you need to first add a shortcode to your page. Once the shortcode is added, you can then click on the “Take Picture” button to capture an image using your webcam. After taking the picture, click on the “Upload” button, which will upload the image to the WP media library. Using the “web_cam_media_id” hook, you can retrieve the media ID of the uploaded image. This media ID can be used to customize various features, such as uploading an avatar image, setting a product image, getting product image feedback, and many more. It is important to note that this plugin is designed to provide a simple and efficient way to upload images using your webcam, and can be customized based on your specific requirements. By using the web_cam_media_id hook, you can easily integrate this plugin into your WordPress website and enhance its functionality. If you need to use the webcam image upload feature on multiple pages or forms within your WordPress website, you can pass a unique slug in the shortcode for each instance. This allows you to differentiate between the various pages or forms and customize the behavior of the plugin accordingly. Once the user takes a picture and uploads it using the plugin, the “web_cam_media_id” action hook is triggered. This hook passes the media ID of the uploaded image as a parameter to any function that is registered to listen for this action. web_cam_media_id use this action to get capture image id on function.php file Shortcode to use: [web-cam] Parameters used within shortcode: – slug For example: [web-cam slug="unique-slug"] add_action(‘web_cam_media_id’,’get_media_id’); function get_media_id($value){ if($value[‘slug’] == ‘home-page’){ print_r($value[‘media_id’]); // if you need only media id $image_url = wp_get_attachment_url($value[‘media_id’]); print_r($image_url); // if you need url of media image } if($value[‘slug’] == ‘contact-page’){ //your custome code to handle media } } you can also design it using css or change the place of button using css For example: if you want to change the take image button’s background-color web_cam is is base id web_cam .takeimage{ background-color: 'black'; } Visit My Upwork Profile-https://www.upwork.com/freelancers/~018f06972fe4607ad0 Which browsers does it support? PC / Mac: – Firefox, Chrome, Safari, Opera, Edge, All Modern Browser Mobile Os: – Android, IOS
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C