VOD Infomaniak Security & Risk Analysis

wordpress.org/plugins/vod-infomaniak

Easily embed and manage videos from Infomaniak VOD in your posts, comments and RSS feeds. You need an Infomaniak VOD account to use this plugin.

20K active installs v1.5.12 PHP + WP 2.8.6+ Updated Oct 6, 2025
infomaniakmanagevideovod
95
A · Safe
CVEs total4
Unpatched0
Last CVESep 23, 2025
Safety Verdict

Is VOD Infomaniak Safe to Use in 2026?

Generally Safe

Score 95/100

VOD Infomaniak has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Sep 23, 2025Updated 6mo ago
Risk Assessment

The "vod-infomaniak" plugin v1.5.13 exhibits a concerning security posture, primarily due to a significant number of unprotected AJAX handlers. The static analysis reveals 10 AJAX handlers with a staggering 8 lacking any form of authentication checks. This creates a large attack surface that could be exploited by unauthenticated users to trigger plugin functionality. Furthermore, the taint analysis shows 8 flows with unsanitized paths, and while no critical or high severity taint flows were detected in this specific analysis, the presence of 8 unsanitized paths is a significant indicator of potential vulnerabilities, especially when combined with the unprotected AJAX endpoints. This suggests a high risk of cross-site scripting (XSS) or other injection attacks if user-supplied data is not properly validated and sanitized before being used in dynamic contexts.

The vulnerability history further compounds these concerns. With a total of 4 known CVEs, including one high-severity and three medium-severity issues, the plugin has a history of security flaws. Common vulnerability types like Cross-Site Scripting, Missing Authorization, and Cross-Site Request Forgery point to recurring weaknesses in how the plugin handles user input and manages access control. The fact that the last vulnerability was dated September 2025 suggests that while there are no currently unpatched CVEs for this version, the plugin has had recent security issues that may indicate a pattern of development that is not prioritizing robust security practices.

In conclusion, while the plugin shows some positive signs like the absence of dangerous functions and a moderate use of prepared statements for SQL queries, the overwhelming number of unprotected AJAX endpoints and the concerning taint analysis results, coupled with a history of multiple vulnerabilities, present a significant risk. The lack of proper authorization on a majority of its entry points is a critical flaw that needs immediate attention. The output escaping is also a weak point, with only 38% properly escaped, increasing the likelihood of XSS vulnerabilities when combined with unsanitized input.

Key Concerns

  • 8 unprotected AJAX handlers
  • 8 unsanitized paths in taint analysis
  • 1 high severity CVE in history
  • 3 medium severity CVEs in history
  • Only 38% properly escaped output
  • 2 file operations
  • Missing nonce checks on 8 AJAX handlers
Vulnerabilities
4

VOD Infomaniak Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2025-62020high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

VOD Infomaniak <= 1.5.11 - Unauthenticated Stored Cross-Site Scripting

Sep 23, 2025 Patched in 1.5.12 (37d)
CVE-2025-22729medium · 4.3Missing Authorization

VOD Infomaniak <= 1.5.9 - Missing Authorization

Jan 14, 2025 Patched in 1.5.10 (8d)
CVE-2024-49274medium · 4.3Cross-Site Request Forgery (CSRF)

VOD Infomaniak <= 1.5.7 - Cross-Site Request Forgery

Oct 14, 2024 Patched in 1.5.8 (5d)
CVE-2024-33571medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

VOD Infomaniak <= 1.5.6 - Reflected Cross-Site Scripting

Apr 25, 2024 Patched in 1.5.7 (532d)
Code Analysis
Analyzed Mar 16, 2026

VOD Infomaniak Code Analysis

Dangerous Functions
0
Raw SQL Queries
35
32 prepared
Unescaped Output
160
100 escaped
Nonce Checks
4
Capability Checks
2
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

48% prepared67 total queries

Output Escaping

38% escaped260 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

9 flows8 with unsanitized paths
importPostVideoEnding (vod.class.php:349)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

VOD Infomaniak Attack Surface

Entry Points10
Unprotected8

AJAX Handlers 10

authwp_ajax_importvodvod.class.php:68
authwp_ajax_vodsearchvideovod.class.php:69
authwp_ajax_vodsearchplaylistvod.class.php:70
authwp_ajax_vodimportvideovod.class.php:71
authwp_ajax_vodimportvideoendingvod.class.php:72
authwp_ajax_vodimportvideodispovod.class.php:73
authwp_ajax_vodimportvideofromurlvod.class.php:74
authwp_ajax_vodgetmediastatevod.class.php:75
authwp_ajax_vodsynchrovideovod.class.php:76
authwp_ajax_vodsharelinkvod.class.php:79
WordPress Hooks 13
actionplugins_loadedvod.class.php:45
actiontemplate_redirectvod.class.php:49
filterquery_varsvod.class.php:50
filterthe_contentvod.class.php:51
filterthe_excerptvod.class.php:52
actionadmin_menuvod.class.php:61
actionedit_form_advancedvod.class.php:62
actionedit_page_formvod.class.php:63
actiondialog-vod-formvod.class.php:64
actionplugins_loadedvod.class.php:82
actionadmin_enqueue_scriptsvod.class.php:85
filtermce_external_pluginsvod.class.php:110
filtermce_buttonsvod.class.php:111
Maintenance & Trust

VOD Infomaniak Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 6, 2025
PHP min version
Downloads279K

Community Trust

Rating80/100
Number of ratings4
Active installs20K
Developer Profile

VOD Infomaniak Developer Profile

Infomaniak Network

1 plugin · 20K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
146 days
View full developer profile
Detection Fingerprints

How We Detect VOD Infomaniak

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vod-infomaniak/css/jquery-ui.css/wp-content/plugins/vod-infomaniak/css/jquery.ui.tabs.css
Script Paths
/wp-content/plugins/vod-infomaniak/js/editor_plugin.js
Version Parameters
vod-infomaniak/css/jquery-ui.css?ver=vod-infomaniak/js/editor_plugin.js?ver=

HTML / DOM Fingerprints

CSS Classes
vod_infomaniak_share_link_modalvod_infomaniak_share_buttonvod_infomaniak_player_wrapper
HTML Comments
<!-- VOD Infomaniak video player --><!-- /VOD Infomaniak video player --><!-- VOD Infomaniak video -->
Data Attributes
data-vod-iddata-vod-player-iddata-vod-playlist-id
JS Globals
vod_infomaniak_ajax_urlvod_infomaniak_nonce
REST Endpoints
/wp-json/vod-infomaniak/v1/get_video/wp-json/vod-infomaniak/v1/get_playlist/wp-json/vod-infomaniak/v1/search
Shortcode Output
[vod_video][vod_playlist]
FAQ

Frequently Asked Questions about VOD Infomaniak