QID 731157
Date Published: 2024-02-15
QID 731157: WordPress HTML5 Video Player Plugin SQL Injection Vulnerability
Play various video files in WordPress. A Simple, accessible Easy-to-use and fully Customizable video player that works on all devices. You can Play embed awesome video players in posts pages widget areas as well as template files.
CVE-2024-1061 : The Html5 Video Player plugin for WordPress is vulnerable to SQL Injection via the id parameter in all versions up to and including 2.5.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
Affected Versions:
WordPress HTML5 Video Player plugin versions prior to 2.5.25
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for HTML5 Video Player Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability may allow unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- WordPress html5-video-player Plugin Release Notes -
wordpress.org/plugins/html5-video-player/#developers
CVEs related to QID 731157
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Html5 Video Player plugin |
|