CVE-2026-62039: WordPress Html5 Audio Player plugin <= 2.8.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.8.8.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vector indicates network reachability, but exploitation requires low-level privileges and user interaction. The vulnerability is stored XSS, so malicious input can be saved and later executed when another user views the affected page or content.
Which versions are affected?
Html5 Audio Player versions through 2.8.8 are affected. The available data does not identify a fixed version.
What is the likely impact?
Successful exploitation can allow script execution in a victim’s browser in the context of the affected WordPress site. The supplied vector indicates low impacts to confidentiality, integrity, and availability, with scope changed.