CVE-2026-24937
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection.
This issue affects Broadcast Live Video: from n/a before 7.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Code Injection vulnerability in WordPress Broadcast Live Video plugin before 7.1.3 allows remote code execution.
Vulnerability
A code injection vulnerability exists in the VideoWhisper.Com Broadcast Live Video plugin for WordPress, affecting versions before 7.1.3. The flaw allows an attacker to inject and execute arbitrary code through improper control of code generation [1]. The vulnerability is present in the plugin's input handling mechanisms, likely triggered via crafted HTTP requests without requiring authentication.
Exploitation
An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable endpoint. No authentication or user interaction is required, making the attack remotely exploitable over the network. The attacker injects malicious code that the plugin then executes within the server context.
Impact
Successful exploitation leads to remote code execution (RCE) on the target WordPress site. The attacker gains the ability to execute arbitrary commands, potentially leading to full site compromise, data theft, website defacement, or further propagation of attacks.
Mitigation
The vulnerability is fixed in version 7.1.3 of the Broadcast Live Video plugin. Users must update to this version or later immediately. If updating is not possible, consider contacting your hosting provider or web developer for assistance. No other workarounds are documented in available references [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <7.1.3
- Range: <7.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.