CVE-2024-5522

MEDIUM NUCLEI

Bplugins Html5 Video Player < 2.5.27 - SQL Injection

Title source: rule

Description

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

Exploits (3)

nomisec SCANNER 10 stars
by geniuszly · poc
https://github.com/geniuszly/CVE-2024-5522
nomisec SCANNER
by kryptonproject · poc
https://github.com/kryptonproject/CVE-2024-5522-PoC
inthewild SCANNER
poc
https://github.com/geniuszlyy/cve-2024-5522

Nuclei Templates (1)

WordPress HTML5 Video Player < 2.5.27 - SQL Injection
CRITICALVERIFIEDby JohnDoeAnonITA

Scores

CVSS v3 6.5
EPSS 0.8384
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-89
Status published
Products (1)
bplugins/html5_video_player < 2.5.27
Published Jun 20, 2024
Tracked Since Feb 18, 2026