CVE-2024-7721: HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'savepassword' function in all versions up to, and including, 2.5.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set any options that are not explicitly checked as false to an array, including enabling user registration if it has been disabled.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7721?
CVE-2024-7721 has a medium severity level due to its potential for unauthorized data modification.
How do I fix CVE-2024-7721?
To fix CVE-2024-7721, update the HTML5 Video Player plugin to version 2.5.35 or later.
Who is affected by CVE-2024-7721?
CVE-2024-7721 affects all versions of the HTML5 Video Player plugin for WordPress up to and including version 2.5.34.
What kind of attack can exploit CVE-2024-7721?
CVE-2024-7721 can be exploited by authenticated users to modify data without proper authorization.
When was CVE-2024-7721 reported?
CVE-2024-7721 was reported in the context of WordPress plugin vulnerabilities, highlighting immediate risks to users.