Target Video Easy Publish
With this plugin, you will be able to seamlessly add TargetVideo video players and your video content to your WordPress website or blog.
TargetVideo has a user-friendly CMS where you can easily upload or import videos and monetize them.
Main Features
- Fast and lightweight HTML5 player
- Full VAST/VPAID support for video monetization
- Full video header bidding support including prebidJS
- Outstream ad units
- Fully customizable player skins
- Responsive player sizing
- Powerful analytics.
Learn more about TargetVideo on our product page.
Users will be able to easily search for videos in their TargetVideo library. In addition all of your playlists and videos will be easily accessible with editable thumbnail, title and other information about the video. Using a simple user interface, click on the video you want and insert it into your post or page.
Default players for videos and playlists can be set throughout the site to create a consistent look as well as default heights and widths which depend on the player setup. All of these defaults can be overridden at the time of video insertion to allow for customization of a video or player.
In addition this plugin features a live preview of the video or playlist and player so you will know that you have the right video before you add it to your site.
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 6.4 MEDIUM | — | ||
The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img’ parameter in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||
| 6.4 MEDIUM | — | ||
The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 3.8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||