The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 May 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prestoplayer
Prestoplayer presto Player |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:prestoplayer:presto_player:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Prestoplayer
Prestoplayer presto Player |
Wed, 30 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-30T13:58:22.162Z
Reserved: 2024-03-13T14:47:52.953Z
Link: CVE-2024-2428
Updated: 2024-08-01T19:11:53.504Z
Status : Analyzed
Published: 2024-04-10T05:15:49.070
Modified: 2025-05-08T21:13:34.010
Link: CVE-2024-2428
No data.
OpenCVE Enrichment
No data.