Vulnerability Description
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bplugins | Html5 Video Player | < 2.5.27 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/bc76ef95-a2a9-4185-8ed9-1059097a506a/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/bc76ef95-a2a9-4185-8ed9-1059097a506a/ExploitThird Party Advisory
FAQ
What is CVE-2024-5522?
CVE-2024-5522 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL inje...
How severe is CVE-2024-5522?
CVE-2024-5522 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5522?
Check the references section above for vendor advisories and patch information. Affected products include: Bplugins Html5 Video Player.