Yahoo! WebPlayer
Yahoo! WebPlayer has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; none of them are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
None of the 2 issues recorded for Yahoo! WebPlayer have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.
All of these findings were reported by johska. Yahoo! WebPlayer is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.3.2.
CVE-2025-53215Yahoo! WebPlayer <= 2.0.6 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Yahoo! WebPlayer
Author
8bitkid
The Yahoo! WebPlayer plugin embeds a media player on your page in a collapsible drawer. This player allows your users to play embedded links on your page to music files, YouTube videos, and Yahoo! movie pages. You can customize many options to uniquely tailor how the player behaves and deals with content. Also, you can provide an Amazon Affiliate Code to monetize purchases made via the plugin. You can find more information on the player at: http://webplayer.yahoo.com/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C