Yahoo! WebPlayer

Yahoo! WebPlayer has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; none of them are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

None of the 2 issues recorded for Yahoo! WebPlayer have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.

All of these findings were reported by johska. Yahoo! WebPlayer is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.3.2.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage0%
Open

2

Fixed

0

Get automatic notifications for all Yahoo! WebPlayer vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2025-53215

Yahoo! WebPlayer <= 2.0.6 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv2.0.6

Yahoo! WebPlayer

8bitkid

Author

8bitkid

0.0(0)
0/100
Last Updated
2012-05-10 (15y ago)
Active Installs
40+
Downloads
27,968
Requires WP
2.0.2+
Requires PHP
0+
Tested up to
WP 3.3.2
Created
2008-02-28 (19y ago)

The Yahoo! WebPlayer plugin embeds a media player on your page in a collapsible drawer. This player allows your users to play embedded links on your page to music files, YouTube videos, and Yahoo! movie pages. You can customize many options to uniquely tailor how the player behaves and deals with content. Also, you can provide an Amazon Affiliate Code to monetize purchases made via the plugin. You can find more information on the player at: http://webplayer.yahoo.com/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C