MediaBlaster – Video CMS, Vimeo Import, Live TV & Podcasts
MediaBlaster – Video CMS, Vimeo Import, Live TV & Podcasts has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for MediaBlaster – Video CMS, Vimeo Import, Live TV & Podcasts has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. MediaBlaster – Video CMS, Vimeo Import, Live TV & Podcasts is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-12818WP Smart TV <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

MediaBlaster – Video CMS, Vimeo Import, Live TV & Podcasts
Author
Rovidx Media, Inc.
MediaBlaster turns WordPress into a structured media CMS for video, podcasts, and scheduled live channels. Manage your catalog, embed native players, import Vimeo libraries, publish podcast RSS feeds, and expose app-ready content through the MediaBlaster REST API. MediaBlaster is the content and configuration layer. It is not a video host or a complete frontend theme. Use a WordPress theme, Gutenberg blocks, Elementor, or a custom website or app to present your content. Bring your own Vimeo account, CDN, or direct HLS, DASH, or MP4 hosting. Core Features Video CMS Manage Movies, Videos, Series, Episodes, metadata, posters, thumbnails, captions, chapter tracks, and HLS, DASH, or MP4 sources. No complete frontend video library layout is included. MediaBlaster Player HLS, DASH, and MP4; Video.js with native fallback; post-backed sources; captions and chapters; locked states when experimental subscriptions are enabled. Shortcode: [mediablaster_player] Channel schedule: [mediablaster_channel_player] Legacy alias: [tv-video-player] Gutenberg blocks: mediablaster/player, mediablaster/channel-player Elementor widget when Elementor is active WordPress-native editing MediaBlaster Player Gutenberg block MediaBlaster Channel Player Gutenberg block MediaBlaster Audio Player Gutenberg block MediaBlaster Player Elementor widget MediaBlaster Audio Player Elementor widget Vimeo integration Opt-in, disabled by default. OAuth; browse/select videos; metadata and thumbnail import; import supported Vimeo playback URLs; review-before-import; bulk import; drafts by default. Playback data depends on account, permissions, and API response. Podcasts Disabled by default. Production-ready shows and episodes, immutable GUIDs, directory-quality RSS, subscriber-aware playback, write-capable podcast REST, RSS diagnostics, and Audio Player ([mediablaster_audio_player], mediablaster/audio-player block, Elementor widget). Live Channels and EPG — Beta Disabled by default. Live streams, Channel Playlists, Channels, weekly scheduler, compiled airings, web Channel player ([mediablaster_channel_player] / mediablaster/channel-player), now/schedule/player REST, EPG/Linear REST, live-channel deep links. Content/schedule/API layer only—not a Pluto TV replacement. REST API and App Config /wp-json/mediablaster/v3/ for content, search, categories, podcasts, channels, EPG, deep links, and app config. See **MediaBlaster → Docs**. Subscription foundation — Developer Preview Disabled by default. Requires WPST_SUBSCRIPTIONS_ENABLED in wp-config.php. Early entitlements, tiers, access groups, subscribers, and Stripe Checkout. Test before production membership use. Extra provider classes are not complete integrations. What You Can Build Content backend for a video library or streaming website Podcast network with RSS and embedded audio players Scheduled live channels with app-ready EPG data Headless media site or content API for apps, including custom Roku apps How MediaBlaster Works MediaBlaster manages content, metadata, players, schedules, feeds, and app configuration in WordPress. The site owner selects and pays for their own media hosting. A theme, page builder, custom frontend, or connected app presents the content. MediaBlaster does not upload, encode, host, or deliver video as a SaaS platform. Use HLS, DASH, or MP4 URLs from compatible hosts. Vimeo is a native opt-in integration; other providers are owner-configured. Optional Roku Launch Kit The free plugin can be the WordPress backend for custom apps. The MediaBlaster Roku Launch Kit is an optional commercial product sold separately. It connects a custom Roku app to MediaBlaster content and App Config and is not included with the WordPress.org plugin: https://www.mediablaster.io/roku-launch-kit External Services Vimeo Contacted only after an administrator enables Vimeo and starts OAuth or import. May transmit client ID, redirect URL, authorization code, and credentials or tokens. Library requests retrieve account/video metadata, thumbnails, tags, descriptions, durations, and playback files from Vimeo. Thumbnail import downloads the remote image. Connection data is stored in options. Activation alone does not connect Vimeo. Vimeo Terms of Service: https://vimeo.com/terms Vimeo Privacy Policy: https://vimeo.com/privacy Stripe For the subscription developer preview only. Contacted when subscriptions are enabled, Stripe credentials are set, and checkout, customer, subscription, or billing-portal actions run. May include name/email, user ID, site URL metadata, Price ID, and return URLs. Stripe returns IDs/statuses; webhooks send events. Checkout/portal users go to Stripe-hosted pages. Activation alone does not contact Stripe. Stripe Services Agreement: https://stripe.com/legal/ssa Stripe Privacy Policy: https://stripe.com/privacy User-selected media hosting During playback, the browser connects to media URLs configured by the site owner. That provider may receive IP, browser, referrer, cookies, or other request data under its terms. MediaBlaster does not auto-select a provider. Site owners document services they configure. Support Built-in docs: MediaBlaster → Docs Product info: https://www.mediablaster.io Free training: https://www.skool.com/ai-content-creators-6489/classroom/44d3f393 WordPress.org support forum for free-plugin questions. License MediaBlaster is licensed under the GPL v2 or later. https://www.gnu.org/licenses/gpl-2.0.html
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C