Skip to content
Noroxi

bPlugins records

22 published records for vendor bplugins.

All records

22 records
  • The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parame

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    bplugins · html5 video playerJan 30, 2024

  • WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    bplugins · icons font loaderNov 6, 2023

  • WordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    bplugins · html5 video playerNov 1, 2024

  • WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    bplugins · button blockJan 15, 2025

  • CVE-2023-5860
    28Monitor

    Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload

    HighCVSS 7.2No exploitEPSS 1%

    bplugins · icons font loaderNov 2, 2023

  • WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload

    HighCVSS 7.2No exploitEPSS 1%

    bplugins · icons font loaderFeb 26, 2024

  • CVE-2024-5522
    27Monitor

    HTML5 Video Player < 2.5.27 - Unauthenticated SQLi

    MediumCVSS 6.5Proof of conceptEPSS 3%

    bplugins · html5 video playerJun 20, 2024

  • Button Block – Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosure

    MediumCVSS 6.5No exploitEPSS 1%

    bplugins · button blockNov 21, 2024

  • Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication

    MediumCVSS 6.5No exploitEPSS 0%

    bplugins · button blockDec 19, 2024

  • WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    bplugins · pdf posterJan 31, 2024

  • Document Embedder < 1.7.5 - Unauthenticated Arbitrary Private/Draft Post Title Disclosure

    MediumCVSS 5.3No exploitEPSS 1%

    bplugins · document embedderFeb 1, 2022

  • Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    bplugins · html5 audio playerOct 18, 2021

  • Easy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    bplugins · easy twitter feedOct 18, 2021

  • StreamCast < 2.1.1 - Contributor+ Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    bplugins · streamcast radio playerOct 18, 2021

  • Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    bplugins · polo video galleryOct 18, 2021

  • CVE-2023-0170
    21Monitor

    Html5 Audio Player < 2.1.12 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    bplugins · html5 audio playerFeb 6, 2023

  • CVE-2023-6485
    21Monitor

    Html5 Video Player < 2.5.19 - Subscriber+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    bplugins · html5 video playerJan 1, 2024

  • CVE-2024-7727
    21Monitor

    HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler

    MediumCVSS 5.3No exploitEPSS 0%

    bplugins · html5 video playerSep 11, 2024

  • WordPress HTML5 Audio Player plugin <= 2.2.23 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    bplugins · html5 audio playerJul 22, 2024

  • WordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    bplugins · button blockJan 9, 2025

  • Document Embedder < 1.7.9 - Subscriber+ Arbitrary Private/Draft Post Title Disclosure

    MediumCVSS 4.3No exploitEPSS 1%

    bplugins · document embedderFeb 1, 2022

  • CVE-2024-7721
    17Monitor

    HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

    MediumCVSS 4.3No exploitEPSS 0%

    bplugins · html5 video playerSep 11, 2024