CVE-2024-1061: Bplugins HTML5 Video Player
Critical severity, CVSS 9.8. EPSS: 11.1% chance of exploitation in the next 30 days.
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.
Affected products
- Bplugins HTML5 Video Player: before 2.5.25 (fixed in 2.5.25)
Published 2024-01-30. Last modified 2026-06-17.