CVE-2024-5522 Information

Description

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement allowing unauthenticated users to perform SQL injection attacks

Reference

https://wpscan.com/vulnerability/bc76ef95-a2a9-4185-8ed9-1059097a506a/

Share on: