CVE-2024-1061 is a critical unauthenticated SQL injection vulnerability affecting the 'HTML5 Video Player' WordPress Plugin versions prior to 2.5.25. This flaw, residing in the 'id' parameter of the 'get_view' function, allows attackers to execute arbitrary SQL commands without authentication. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, successful exploitation could lead to full compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, Nuclei templates exist for detecting this vulnerability, and its FAUCET Risk Score is 99/100, indicating a severe threat. There is currently no evidence of active exploitation, Metasploit modules, or ExploitDB entries, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.25CPE matchmatch criteria | cpe:2.3:a:bplugins:html5_video_player:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.