CVE-2024-43319: WordPress HTML5 Video Player plugin <= 2.5.31 - Sensitive Data Exposure vulnerability
Published Aug 26, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.
Affected Software
2 affected components
bPlugins LLC Flash & HTML5 Video>=n/a, <=2.5.31
WordPress HTML5 Video Player<=2.5.31
Remediation
Information
Update to 2.5.32 or a higher version.
Event History
Aug 26, 2024
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43319?
CVE-2024-43319 has a high severity level due to the exposure of sensitive information to unauthorized actors.
2
How do I fix CVE-2024-43319?
To fix CVE-2024-43319, update the bPlugins LLC Flash & HTML5 Video plugin to version 2.5.32 or later.
3
What systems are affected by CVE-2024-43319?
CVE-2024-43319 affects bPlugins LLC Flash & HTML5 Video versions from n/a to 2.5.31 and WordPress HTML5 Video Player up to version 2.5.31.
4
What types of sensitive information could be exposed by CVE-2024-43319?
CVE-2024-43319 can expose sensitive user data, including personal identifiers and any data configured to be private.
5
Is it safe to continue using affected plugins after the CVE-2024-43319 discovery?
No, it is not safe to continue using affected plugins without applying the necessary updates immediately.