CVE-2024-5522 is a SQL injection vulnerability affecting the HTML5 Video Player WordPress plugin versions prior to 2.5.27. Unauthenticated attackers can exploit a REST route parameter that is not properly sanitized, allowing them to perform SQL injection attacks. Rated Medium severity (CVSS 6.5), this vulnerability has a high FAUCET Risk Score of 99/100 and a high EPSS score, indicating a significant likelihood of exploitation. While not currently in the KEV catalog and with no Metasploit or ExploitDB entries, Nuclei templates exist for this critical vulnerability, suggesting readily available exploit code. There is currently no public community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.27CPE matchmatch criteria | cpe:2.3:a:bplugins:html5_video_player:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.