VendorsbPluginshtml5_video_playerall versions
Vulnerabilities

bPlugins Html5 Video Player

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-1061
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.
Published 2024-01-30 · Modified
9.8EPSS 0.112
CVE-2024-43296
WordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerability
Published 2024-11-01 · Analyzed
8.8EPSS 0.004
CVE-2024-5522
HTML5 Video Player < 2.5.27 - Unauthenticated SQLi
Published 2024-06-20 · Analyzed
6.5EPSS 0.026
CVE-2023-6485
Html5 Video Player < 2.5.19 - Subscriber+ Stored XSS
Published 2024-01-01 · Modified
5.4EPSS 0.005
CVE-2024-7727
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler
Published 2024-09-11 · Analyzed
5.3EPSS 0.004
CVE-2024-7721
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
Published 2024-09-11 · Analyzed
4.3EPSS 0.003