CVE-2025-39524: WordPress Html5 Audio Player plugin <= 2.2.28 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in bPlugins Html5 Audio Player allows Stored XSS. This issue affects Html5 Audio Player: from n/a through 2.2.28.
Other sources
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through <= 2.2.28.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39524?
CVE-2025-39524 is considered a critical vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-39524?
To mitigate CVE-2025-39524, update the bPlugins Html5 Audio Player to version 2.2.29 or later.
Which software is affected by CVE-2025-39524?
CVE-2025-39524 affects the bPlugins Html5 Audio Player and WordPress Html5 Audio Player versions up to and including 2.2.28.
What impact does CVE-2025-39524 have on users?
The vulnerability allows attackers to execute arbitrary JavaScript in the context of the user's browser, potentially leading to unauthorized data access.
Is there a known exploit for CVE-2025-39524?
While there are no specific exploits publicly disclosed for CVE-2025-39524, its nature as an XSS vulnerability poses significant risk.