The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute
medium
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url sh...
- CVSS:
- 6.4
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.1
- Disclosed:
- Jun 11, 2026
CVE-2026-9125 on NVD →
The Ultimate Video Player For WordPress – by Presto Player <= 4.1.3 - Missing Authorization
medium
The The Ultimate Video Player For WordPress – by Presto Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- May 19, 2026
CVE-2026-45442 on NVD →
The Ultimate Video Player For WordPress – by Presto Player [presto-player] < 3.0.3
unknown
[en] Missing Authorization vulnerability in Presto Made, Inc Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Presto Player: from n/a through 3.0.2.
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Nov 1, 2024
CVE-2024-43285 on NVD →
Presto Player <= 3.0.2 - Missing Authorization
medium
The Presto Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Aug 16, 2024
CVE-2024-43285 on NVD →
Presto Player < 3.0.3 - Missing Authorization
medium
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Aug 16, 2024
CVE-2024-43285 on NVD →
The Ultimate Video Player For WordPress – by Presto Player [presto-player] < 2.2.3
unknown
[en] The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS...
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Apr 10, 2024
CVE-2024-2428 on NVD →
The Ultimate Video Player For WordPress <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Ultimate Video Player For WordPress – by Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in all versions up to, and including, 2.2.2 due to missing authorization on a REST API endpoint and insufficient input sanitization and output escaping on the setti...
- CVSS:
- 6.4
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Mar 20, 2024
CVE-2024-2428 on NVD →
The Ultimate Video Player For WordPress < 2.2.3 - Contributor+ Stored XSS
medium
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Mar 20, 2024
CVE-2024-2428 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database