CVE-2024-5522
MEDIUM 6.5EPSS 2.6%
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 2.62% chance of exploitation in the next 30 days, 84th percentile
- Nuclei
- critical · CWE-89
- Published
- 2024-06-20
- Updated
- 2024-08-01
Proof-of-concept exploits (4)
- https://wpscan.com/vulnerability/bc76ef95-a2a9-4185-8ed9-1059097a506a/
- geniuszly/CVE-2024-552210★ · 2024-10-01
- geniuszlyy/CVE-2024-552210★ · 2024-10-01
- kryptonproject/CVE-2024-5522-PoC0★ · 2024-09-11