QID 731157

Date Published: 2024-02-15

QID 731157: WordPress HTML5 Video Player Plugin SQL Injection Vulnerability

Play various video files in WordPress. A Simple, accessible Easy-to-use and fully Customizable video player that works on all devices. You can Play embed awesome video players in posts pages widget areas as well as template files.

CVE-2024-1061 : The Html5 Video Player plugin for WordPress is vulnerable to SQL Injection via the id parameter in all versions up to and including 2.5.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

Affected Versions:
WordPress HTML5 Video Player plugin versions prior to 2.5.25

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for HTML5 Video Player Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to WP Booking version 2.5.25 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731157

    Software Advisories
    Advisory ID Software Component Link
    Html5 Video Player plugin URL Logo wordpress.org/plugins/html5-video-player/#developers