Description
Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects H5P: from n/a through <= 1.16.1.
Published: 2025-12-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The icc0rz H5P WordPress plugin contains a missing authorization flaw, identified as CWE‑862. The vulnerability allows a user with limited permissions to perform actions that should be reserved for higher‑privilege accounts. Likely, an attacker could view, edit, or delete content managed by H5P, thereby compromising the integrity and confidentiality of site data. The flaw does not grant full‑system control, but it does enable unauthorized access within the plugin’s scope.

Affected Systems

The affected product is the H5P WordPress plugin distributed by icc0rz. All releases from the earliest available version up to and including version 1.16.1 are vulnerable. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker has some level of access to the WordPress site—either through an existing user account that can manipulate the plugin or by leveraging another authentication issue to gain sufficient privileges. The flaw allows privilege escalation within the plugin’s functions but does not enable remote code execution. Monitoring user accounts and reviewing plugin permissions is advisable.

Generated by OpenCVE AI on April 29, 2026 at 22:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the H5P plugin to a version newer than 1.16.1 that contains the authorization fix
  • Restrict the use of the H5P plugin to administrator‑level WordPress accounts and review its security levels
  • Deactivate or uninstall the H5P plugin if it is not required for site functionality

Generated by OpenCVE AI on April 29, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared H5p
H5p h5p
Wordpress
Wordpress wordpress
Vendors & Products H5p
H5p h5p
Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects H5P: from n/a through <= 1.16.1.
Title WordPress H5P plugin <= 1.16.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:29.071Z

Reserved: 2025-12-19T10:16:51.230Z

Link: CVE-2025-68505

cve-icon Vulnrichment

Updated: 2025-12-24T19:12:17.837Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:20.400

Modified: 2026-04-27T19:16:25.937

Link: CVE-2025-68505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:15:16Z

Weaknesses