First published: Tue Jan 30 2024(Updated: )
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bplugins Html5 Video Player | <2.5.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1061 is considered a critical severity vulnerability due to its potential for unauthenticated SQL injection.
To fix CVE-2024-1061, upgrade the 'HTML5 Video Player' WordPress Plugin to version 2.5.25 or later.
CVE-2024-1061 can be exploited through an unauthenticated SQL injection attack targeting the 'id' parameter in the 'get_view' function.
Users of the 'HTML5 Video Player' WordPress Plugin versions earlier than 2.5.25 are affected by CVE-2024-1061.
CVE-2024-1061 impacts the ability of the plugin to handle requests securely, potentially exposing database information.