CVE-2024-1061: Bplugins HTML5 Video Player

Critical severity, CVSS 9.8. EPSS: 11.1% chance of exploitation in the next 30 days.

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.

Affected products

  • Bplugins HTML5 Video Player: before 2.5.25 (fixed in 2.5.25)

Published 2024-01-30. Last modified 2026-06-17.