HTML5 Video Player – Embed and Play Videos in Custom Player <= 2.11.0 - Missing Authorization
medium
The HTML5 Video Player – Embed and Play Videos in Custom Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.11.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.1
- Disclosed:
- Jun 26, 2026
CVE-2026-57323 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.36
unknown
[en] The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘heading’ parameter in all versions up to, and including, 2.5.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- Affected:
- up to 2.5.36
- Fixed in:
- 2.5.36
- Disclosed:
- Jan 14, 2025
CVE-2024-13156 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.35 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via heading Parameter
medium
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘heading’ parameter in all versions up to, and including, 2.5.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 2.5.35
- Fixed in:
- 2.5.36
- Disclosed:
- Jan 13, 2025
CVE-2024-13156 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.31
unknown
[en] Missing Authorization vulnerability in bPlugins LLC Flash & HTML5 Video allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flash & HTML5 Video: from n/a through 2.5.30.
- Affected:
- up to 2.5.31
- Fixed in:
- 2.5.31
- Disclosed:
- Nov 1, 2024
CVE-2024-43296 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.33
unknown
[en] The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32. This makes it possible for unauthenticate...
- Affected:
- up to 2.5.33
- Fixed in:
- 2.5.33
- Disclosed:
- Sep 11, 2024
CVE-2024-7727 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.35
unknown
[en] The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34. This makes it possible for authenticated attackers, with Subscriber-leve...
- Affected:
- up to 2.5.35
- Fixed in:
- 2.5.35
- Disclosed:
- Sep 11, 2024
CVE-2024-7721 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
medium
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34. This makes it possible for authenticated attackers, with Subscriber-level acc...
- CVSS:
- 4.3
- Affected:
- up to 2.5.34
- Fixed in:
- 2.5.35
- Disclosed:
- Sep 10, 2024
CVE-2024-7721 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler
medium
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32. This makes it possible for unauthenticated att...
- CVSS:
- 5.3
- Affected:
- up to 2.5.32
- Fixed in:
- 2.5.33
- Disclosed:
- Sep 10, 2024
CVE-2024-7727 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.32
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.
- Affected:
- up to 2.5.32
- Fixed in:
- 2.5.32
- Disclosed:
- Aug 26, 2024
CVE-2024-43319 on NVD →
Flash & HTML5 Video <= 2.5.30 - Missing Authorization
medium
The Flash & HTML5 Video plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in versions up to, and including, 2.5.30. This makes it possible for authenticated attackers, with subscriber-level access and above, to update views, create thumbnails, and more.
- CVSS:
- 6.4
- Affected:
- up to 2.5.30
- Fixed in:
- 2.5.31
- Disclosed:
- Aug 16, 2024
CVE-2024-43296 on NVD →
Flash & HTML5 Video <= 2.5.31 - Authenticated (Subscriber+) Information Exposure
medium
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.31 via the h5vp_export_data() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract potenti...
- CVSS:
- 4.3
- Affected:
- up to 2.5.31
- Fixed in:
- 2.5.32
- Disclosed:
- Aug 16, 2024
CVE-2024-43319 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.27
unknown
[en] The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
- Affected:
- up to 2.5.27
- Fixed in:
- 2.5.27
- Disclosed:
- Jun 20, 2024
CVE-2024-5522 on NVD →
HTML5 Video Player <= 2.5.26 - Unauthenticated SQL Injection
critical
The HTML5 Video Player – Best WordPress Video Player Plugin and Block plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.26 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unaut...
- CVSS:
- 10
- Affected:
- up to 2.5.26
- Fixed in:
- 2.5.27
- Disclosed:
- May 30, 2024
CVE-2024-5522 on NVD →
HTML5 Video Player <= 2.5.24 - Unauthenticated SQL Injection via id
medium
The Html5 Video Player plugin for WordPress is vulnerable to SQL Injection via the 'id’ parameter in all versions up to, and including, 2.5.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers t...
- CVSS:
- 6.5
- Affected:
- up to 2.5.24
- Fixed in:
- 2.5.25
- Disclosed:
- Jan 31, 2024
CVE-2024-1061 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.25
unknown
[en] The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.
- Affected:
- up to 2.5.25
- Fixed in:
- 2.5.25
- Disclosed:
- Jan 30, 2024
CVE-2024-1061 on NVD →
HTML5 Video Player – mp4 Video Player Plugin and Block [html5-video-player] < 2.5.19
unknown
[en] The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users...
- Affected:
- up to 2.5.19
- Fixed in:
- 2.5.19
- Disclosed:
- Jan 1, 2024
CVE-2023-6485 on NVD →
Html5 Video Player <= 2.5.18 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Html5 Video Player – mp4 player, Video Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions...
- CVSS:
- 6.4
- Affected:
- up to 2.5.18
- Fixed in:
- 2.5.19
- Disclosed:
- Dec 8, 2023
CVE-2023-6485 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database