SQL Injection Vulnerability in HTML5 Video Player WordPress Plugin
CVE-2024-5522

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 June 2024

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐Ÿ“ฐ News Worthy

Summary

The CVE-2024-5522 vulnerability is a SQL injection vulnerability in the HTML5 Video Player WordPress plugin before version 2.5.27. This vulnerability allows unauthenticated users to perform SQL injection attacks. This has not been exploited in the wild and there is no information about ransomware groups exploiting it. However, it is important to address this vulnerability as it could have a significant impact on the affected systems.

Affected Version(s)

HTML5 Video Player 0 < 2.5.27

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Pentest-Tools.com

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mayank Deshmukh
WPScan
.