← Back

Html5 Video Player

html5_video_player

Vendor: Bplugins • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bplugins
1Html5 Video Player
Nov 13, 2024
Nov 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Missing Authorization vulnerability in bPlugins LLC Flash & HTML5 Video allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flash & HTML5 Video: from n/a through 2.5.30.
1Bplugins
1Html5 Video Player
Sep 18, 2024
Sep 11, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax...Show more
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32. This makes it possible for unauthenticated attackers to call these functions to manipulate data.Show less
1Bplugins
1Html5 Video Player
Sep 18, 2024
Sep 11, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to,...Show more
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set any options that are not explicitly checked as false to an array, including enabling user registration if it has been disabled.Show less
1Bplugins
1Html5 Video Player
May 19, 2025
Jun 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
1Bplugins
1Html5 Video Player
Nov 21, 2024
Jan 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.
1Bplugins
1Html5 Video Player
Jun 18, 2025
Jan 1, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as...Show more
The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like adminsShow less