CVE-2024-1061
bplugins html5_video_player Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2024-1061 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 14, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
html5_video_playerBrowse bplugins / html5_video_player | VulnCheck | Version data not supplied | |
html5-video-playerDefault status: unaffected | CVE List | Before 2.5.25 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress HTML5 Video Player - SQL InjectionCVSS 9.8
WordPress HTML5 Video Player plugin is vulnerable to SQL injection. An unauthenticated attacker can exploit this vulnerability to perform SQL injection attacks.
Impact
Successful exploitation of this vulnerability could allow an attacker to perform SQL injection attacks, potentially leading to unauthorized access, data leakage, or further compromise of the WordPress site.
Remediation
Vendor did not acknowledge vulnerability but the issue seems to have been fixed in version 2.5.25.
Source: ProjectDiscovery