First published: Mon Feb 06 2023(Updated: )
The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bplugins Html5 Audio Player | <2.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0170 is a vulnerability found in the Html5 Audio Player WordPress plugin before version 2.1.12.
The severity of CVE-2023-0170 is medium, with a CVSS score of 5.4.
The affected software for CVE-2023-0170 is the Html5 Audio Player WordPress plugin before version 2.1.12.
CVE-2023-0170 is a Stored Cross-Site Scripting vulnerability in the Html5 Audio Player WordPress plugin before version 2.1.12, which could be exploited by users with the contributor role or above.
To fix CVE-2023-0170, update the Html5 Audio Player WordPress plugin to version 2.1.12 or higher.