← Back

Bplugins

bplugins

22 CVEs • 9 products

Products (9)

Click to collapse
Toggle

CVEs (22)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bplugins
1Button Block
Apr 23, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through <= 1.1.5.
1Bplugins
1Button Block
Apr 23, 2026
Jan 9, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Button Block button-block allows Stored XSS.This issue affects Button Block: from n/a through <= 1.1.9.
1Bplugins
1Button Block
Feb 28, 2025
Dec 19, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the 'btn_block_duplicate_post' fun...Show more
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the 'btn_block_duplicate_post' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.Show less
1Bplugins
1Button Block
Feb 27, 2025
Nov 21, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.4 via the [btn_block] shortcode due to insufficien...Show more
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.4 via the [btn_block] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.Show less
1Bplugins
1Html5 Video Player
Nov 13, 2024
Nov 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Missing Authorization vulnerability in bPlugins LLC Flash & HTML5 Video allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flash & HTML5 Video: from n/a through 2.5.30.
1Bplugins
1Html5 Video Player
Sep 18, 2024
Sep 11, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax...Show more
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32. This makes it possible for unauthenticated attackers to call these functions to manipulate data.Show less
1Bplugins
1Html5 Video Player
Sep 18, 2024
Sep 11, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to,...Show more
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set any options that are not explicitly checked as false to an array, including enabling user registration if it has been disabled.Show less
1Bplugins
1Html5 Audio Player
Nov 21, 2024
Jul 22, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23.
1Bplugins
1Html5 Video Player
May 19, 2025
Jun 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
1Bplugins
1Icons Font Loader
Apr 28, 2026
Feb 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.
1Bplugins
1Pdf Poster
Apr 28, 2026
Jan 31, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins PDF Poster – PDF Embedder Plugin for WordPress allows Reflected XSS.This issue affects PDF Poster – PDF Embed...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins PDF Poster – PDF Embedder Plugin for WordPress allows Reflected XSS.This issue affects PDF Poster – PDF Embedder Plugin for WordPress: from n/a through 2.1.17.Show less
1Bplugins
1Html5 Video Player
Nov 21, 2024
Jan 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.
1Bplugins
1Html5 Video Player
Jun 18, 2025
Jan 1, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as...Show more
The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like adminsShow less
1Bplugins
1Icons Font Loader
Apr 29, 2026
Nov 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.
1Bplugins
1Icons Font Loader
Apr 8, 2026
Nov 2, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authen...Show more
The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.Show less
1Bplugins
1Html5 Audio Player
Mar 25, 2025
Feb 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with th...Show more
The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Show less
1Bplugins
1Document Embedder
Nov 21, 2024
Feb 1, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
1Bplugins
1Document Embedder
Nov 21, 2024
Feb 1, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
1Bplugins
1Streamcast Radio Player
Nov 21, 2024
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in the...Show more
The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcodeShow less
1Bplugins
1Polo Video Gallery
Nov 21, 2024
Oct 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Sit...Show more
The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcodeShow less