CVE-2024-1061

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 30, 2024
Published Date
January 30, 2024
Last Updated
November 12, 2024
Vendor
bPlugins
Product
html5-video-player
Description
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.
Tags
wordpress nuclei_scanner

CVSS Scores

CVSS v3.1

8.6 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS Score

Score
80.43% (Percentile: 99.06%) as of 2025-05-24

SSVC Information

Exploitation
none
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2025-05-10 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-05-10 00:00:00 UTC

Scanner Integrations