Radio Station lets you build and manage a Show Schedule for a radio station or Internet broadcaster's WordPress website.
Qué hace este plugin
- Slug:
radio-station
- Autor: Tony Zeoli
- 1000+ instalaciones activas
- 92/100 calificación (30 reseñas en wordpress.org)
- 153441 descargas totales
- En WordPress.org desde 2013-02-25
radio broadcastingradio showsRadio stationradio station schedulestreaming radio player
Estado de mantenimiento
- Última actualización: 2026-06-28 12:34pm GMT
- Probado hasta WordPress: 7.0.2
Vulnerabilidades conocidas
5 CVEs conocidos registrados para Radio Station.
Reportadas entre 2022 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-13362
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.5.17 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.5.17
|
2.5.17 |
2026-04-30 |
—
|
|
CVE-2025-53568
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.5.13 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.5.13
|
2.5.13 |
2025-07-03 |
—
|
|
CVE-2024-33689
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.5.8 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.5.8
|
2.5.8 |
2024-04-26 |
—
|
|
CVE-2023-33999
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.5.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 2.5.5
|
2.5.5 |
2023-07-18 |
—
|
|
CVE-2023-32499
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.5.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 2.5.0
|
2.5.0 |
2023-05-09 |
—
|
|
—
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.4.0.6 |
Falta de control de autorización |
Media
6,3
|
< 2.4.0.6
|
2.4.0.6 |
2022-03-04 |
—
|
|
—
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.4.0.6 |
— |
Desconocido
|
< 2.4.0.6
|
2.4.0.6 |
2022-02-28 |
—
|
|
—
|
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.4.0.6 |
— |
Desconocido
|
< 2.4.0.6
|
2.4.0.6 |
2022-02-28 |
—
|
CVE-2024-13362
Varios plugins y/o temas para WordPress son vulnerables a Reflected Cross-Site Scripting (XSS) a través del parámetro url en diversas versiones debido a una sanitización de entrada insuficiente y un escape de salida inadecuado. Esto permite que atacantes no autenticados inyecten scripts web arbitrarios en páginas que se ejecutan si pueden engañar a un usuario para que realice una acción, como hacer clic en un enlace.
Traducción automática del texto original de la fuente.
Ver original
Fuente:
CVE.org
CVE-2025-53568
The Radio Station by netmix® – Manage and play your Show Schedule in WordPress! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.12. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-33689
The Radio Station by netmix® – Manage and play your Show Schedule in WordPress! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.7. This is due to missing or incorrect nonce validation on the radio_station_notice_dismiss() function. This makes it possible for unauthenticated attackers to dismiss notices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-33999
No patched version available.
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Radio Station Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has not been known to be fixed yet.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-32499
Update the WordPress Radio Station plugin to the latest available version (at least 2.5.0).
minhtuanact discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Radio Station Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.5.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.4.0.6
El SDK de Freemius, utilizado por cientos de desarrolladores de plugins y temas de WordPress, estaba expuesto a Cross-Site Request Forgery (CSRF) y revelación de información debido a la falta de comprobaciones de capacidad y protección con nonce en las funciones _get_debug_log, _get_db_option y _set_db_option en versiones hasta y inclusive 2.4.2. Cualquier plugin o tema de WordPress que ejecute una versión de Freemius menor a 2.4.3 es vulnerable.
Traducción automática del texto original de la fuente.
Ver original
Fuente:
Wordfence
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.4.0.6
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Radio Station plugin (versions <= 2.4.0.5).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! [radio-station] < 2.4.0.6
Sensitive Information Disclosure vulnerability discovered in WordPress Radio Station plugin (versions <= 2.4.0.5).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.