plugin

Presto Player Vulnerabilities

8 known security issues reported for the Presto Player WordPress plugin. Most recent disclosed Jun 11, 2026.

6 medium

Running Presto Player on your site? Check whether your installed version is affected.

Scan your site free

The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute

medium

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url sh...

CVSS:
6.4
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Jun 11, 2026

CVE-2026-9125 on NVD →

The Ultimate Video Player For WordPress – by Presto Player <= 4.1.3 - Missing Authorization

medium

The The Ultimate Video Player For WordPress – by Presto Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.1.3
Fixed in:
4.1.4
Disclosed:
May 19, 2026

CVE-2026-45442 on NVD →

The Ultimate Video Player For WordPress &#8211; by Presto Player [presto-player] < 3.0.3

unknown

[en] Missing Authorization vulnerability in Presto Made, Inc Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Presto Player: from n/a through 3.0.2.

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Nov 1, 2024

CVE-2024-43285 on NVD →

Presto Player <= 3.0.2 - Missing Authorization

medium

The Presto Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Aug 16, 2024

CVE-2024-43285 on NVD →

Presto Player < 3.0.3 - Missing Authorization

medium
Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Aug 16, 2024

CVE-2024-43285 on NVD →

The Ultimate Video Player For WordPress &#8211; by Presto Player [presto-player] < 2.2.3

unknown

[en] The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Apr 10, 2024

CVE-2024-2428 on NVD →

The Ultimate Video Player For WordPress <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Ultimate Video Player For WordPress – by Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in all versions up to, and including, 2.2.2 due to missing authorization on a REST API endpoint and insufficient input sanitization and output escaping on the setti...

CVSS:
6.4
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Mar 20, 2024

CVE-2024-2428 on NVD →

The Ultimate Video Player For WordPress < 2.2.3 - Contributor+ Stored XSS

medium
Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Mar 20, 2024

CVE-2024-2428 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database