Vulnerabilities > Bplugins > Html5 Video Player > 2.5.23

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-43296 Missing Authorization vulnerability in Bplugins Html5 Video Player
Missing Authorization vulnerability in bPlugins LLC Flash & HTML5 Video allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flash & HTML5 Video: from n/a through 2.5.30.
network
low complexity
bplugins CWE-862
8.8
2024-09-11 CVE-2024-7721 Missing Authorization vulnerability in Bplugins Html5 Video Player
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34.
network
low complexity
bplugins CWE-862
4.3
2024-09-11 CVE-2024-7727 Missing Authorization vulnerability in Bplugins Html5 Video Player
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32.
network
low complexity
bplugins CWE-862
5.3
2024-01-30 CVE-2024-1061 SQL Injection vulnerability in Bplugins Html5 Video Player
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.
network
low complexity
bplugins CWE-89
critical
9.8