The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Prestoplayer
Prestoplayer presto Player |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:prestoplayer:presto_player:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Prestoplayer
Prestoplayer presto Player |
Wed, 30 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-04-10T05:00:02.711Z
Updated: 2024-10-30T13:58:22.162Z
Reserved: 2024-03-13T14:47:52.953Z
Link: CVE-2024-2428

Updated: 2024-08-01T19:11:53.504Z

Status : Analyzed
Published: 2024-04-10T05:15:49.070
Modified: 2025-05-08T21:13:34.010
Link: CVE-2024-2428

No data.