PT-2024-38534 · WordPress · Html5 Video Player – Mp4 Video Player Plugin

Lucio Sá

·

Published

2024-09-11

·

Updated

2024-09-18

·

CVE-2024-7721

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress versions up to, and including, 2.5.34
Description The issue is related to unauthorized modification of data due to a missing capability check on the save password function. This allows authenticated attackers with Subscriber-level access and above to set any options that are not explicitly checked as false to an array. This includes enabling user registration if it has been disabled.
Recommendations For versions up to, and including, 2.5.34, consider disabling the save password function until a patch is available to prevent unauthorized modification of data. Restrict access to options that can be modified through this function to minimize the risk of exploitation. Avoid using the save password function in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7721

Affected Products

Html5 Video Player – Mp4 Video Player Plugin