bPlugins records
22 published records for vendor bplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-862 Missing Authorization4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2024-1061Proof of concept | The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' paramebplugins · html5 video player · CWE-89 | Critical9.8 | — | 11.2% | Jan 30, 2024 |
35Monitor | CVE-2023-46084No exploit | WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injectionbplugins · icons font loader · CWE-89 | High8.8 | — | 0.5% | Nov 6, 2023 |
35Monitor | CVE-2024-43296No exploit | WordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerabilitybplugins · html5 video player · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
35Monitor | CVE-2025-22787No exploit | WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerabilitybplugins · button block · CWE-862 | High8.8 | — | 0.3% | Jan 15, 2025 |
28Monitor | CVE-2023-5860No exploit | Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Uploadbplugins · icons font loader · CWE-434 | High7.2 | — | 1.0% | Nov 2, 2023 |
28Monitor | CVE-2024-24714No exploit | WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Uploadbplugins · icons font loader · CWE-434 | High7.2 | — | 0.6% | Feb 26, 2024 |
27Monitor | CVE-2024-5522Proof of concept | HTML5 Video Player < 2.5.27 - Unauthenticated SQLibplugins · html5 video player · CWE-89 | Medium6.5 | — | 2.6% | Jun 20, 2024 |
26Monitor | CVE-2024-10671No exploit | Button Block – Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosurebplugins · button block · CWE-639 | Medium6.5 | — | 0.5% | Nov 21, 2024 |
26Monitor | CVE-2024-12560No exploit | Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplicationbplugins · button block · CWE-200 | Medium6.5 | — | 0.4% | Dec 19, 2024 |
24Monitor | CVE-2024-23508No exploit | WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS)bplugins · pdf poster · CWE-79 | Medium6.1 | — | 0.3% | Jan 31, 2024 |
21Monitor | CVE-2021-24775No exploit | Document Embedder < 1.7.5 - Unauthenticated Arbitrary Private/Draft Post Title Disclosurebplugins · document embedder · CWE-668 | Medium5.3 | — | 1.3% | Feb 1, 2022 |
21Monitor | CVE-2021-24412No exploit | Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scriptingbplugins · html5 audio player · CWE-79 | Medium5.4 | — | 0.7% | Oct 18, 2021 |
21Monitor | CVE-2021-24413No exploit | Easy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site Scriptingbplugins · easy twitter feed · CWE-79 | Medium5.4 | — | 0.7% | Oct 18, 2021 |
21Monitor | CVE-2021-24416No exploit | StreamCast < 2.1.1 - Contributor+ Stored Cross-Site Scriptingbplugins · streamcast radio player · CWE-79 | Medium5.4 | — | 0.6% | Oct 18, 2021 |
21Monitor | CVE-2021-24415No exploit | Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site Scriptingbplugins · polo video gallery · CWE-79 | Medium5.4 | — | 0.6% | Oct 18, 2021 |
21Monitor | CVE-2023-0170No exploit | Html5 Audio Player < 2.1.12 - Contributor+ Stored XSSbplugins · html5 audio player · CWE-79 | Medium5.4 | — | 0.6% | Feb 6, 2023 |
21Monitor | CVE-2023-6485No exploit | Html5 Video Player < 2.5.19 - Subscriber+ Stored XSSbplugins · html5 video player · CWE-79 | Medium5.4 | — | 0.5% | Jan 1, 2024 |
21Monitor | CVE-2024-7727No exploit | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handlerbplugins · html5 video player · CWE-862 | Medium5.3 | — | 0.4% | Sep 11, 2024 |
21Monitor | CVE-2024-37445No exploit | WordPress HTML5 Audio Player plugin <= 2.2.23 - Cross Site Scripting (XSS) vulnerabilitybplugins · html5 audio player · CWE-79 | Medium5.4 | — | 0.3% | Jul 22, 2024 |
21Monitor | CVE-2025-22815No exploit | WordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerabilitybplugins · button block · CWE-79 | Medium5.4 | — | 0.2% | Jan 9, 2025 |
17Monitor | CVE-2021-24868No exploit | Document Embedder < 1.7.9 - Subscriber+ Arbitrary Private/Draft Post Title Disclosurebplugins · document embedder · CWE-668 | Medium4.3 | — | 0.9% | Feb 1, 2022 |
17Monitor | CVE-2024-7721No exploit | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Updatebplugins · html5 video player · CWE-862 | Medium4.3 | — | 0.3% | Sep 11, 2024 |
- CVE-2024-106142Plan
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parame
CriticalCVSS 9.8Proof of conceptEPSS 11%bplugins · html5 video playerJan 30, 2024
- CVE-2023-4608435Monitor
WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%bplugins · icons font loaderNov 6, 2023
- CVE-2024-4329635Monitor
WordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%bplugins · html5 video playerNov 1, 2024
- CVE-2025-2278735Monitor
WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%bplugins · button blockJan 15, 2025
- CVE-2023-586028Monitor
Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%bplugins · icons font loaderNov 2, 2023
- CVE-2024-2471428Monitor
WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%bplugins · icons font loaderFeb 26, 2024
- CVE-2024-552227Monitor
HTML5 Video Player < 2.5.27 - Unauthenticated SQLi
MediumCVSS 6.5Proof of conceptEPSS 3%bplugins · html5 video playerJun 20, 2024
- CVE-2024-1067126Monitor
Button Block – Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosure
MediumCVSS 6.5No exploitEPSS 1%bplugins · button blockNov 21, 2024
- CVE-2024-1256026Monitor
Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication
MediumCVSS 6.5No exploitEPSS 0%bplugins · button blockDec 19, 2024
- CVE-2024-2350824Monitor
WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%bplugins · pdf posterJan 31, 2024
- CVE-2021-2477521Monitor
Document Embedder < 1.7.5 - Unauthenticated Arbitrary Private/Draft Post Title Disclosure
MediumCVSS 5.3No exploitEPSS 1%bplugins · document embedderFeb 1, 2022
- CVE-2021-2441221Monitor
Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%bplugins · html5 audio playerOct 18, 2021
- CVE-2021-2441321Monitor
Easy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%bplugins · easy twitter feedOct 18, 2021
- CVE-2021-2441621Monitor
StreamCast < 2.1.1 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%bplugins · streamcast radio playerOct 18, 2021
- CVE-2021-2441521Monitor
Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%bplugins · polo video galleryOct 18, 2021
- CVE-2023-017021Monitor
Html5 Audio Player < 2.1.12 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%bplugins · html5 audio playerFeb 6, 2023
- CVE-2023-648521Monitor
Html5 Video Player < 2.5.19 - Subscriber+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%bplugins · html5 video playerJan 1, 2024
- CVE-2024-772721Monitor
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler
MediumCVSS 5.3No exploitEPSS 0%bplugins · html5 video playerSep 11, 2024
- CVE-2024-3744521Monitor
WordPress HTML5 Audio Player plugin <= 2.2.23 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%bplugins · html5 audio playerJul 22, 2024
- CVE-2025-2281521Monitor
WordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%bplugins · button blockJan 9, 2025
- CVE-2021-2486817Monitor
Document Embedder < 1.7.9 - Subscriber+ Arbitrary Private/Draft Post Title Disclosure
MediumCVSS 4.3No exploitEPSS 1%bplugins · document embedderFeb 1, 2022
- CVE-2024-772117Monitor
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
MediumCVSS 4.3No exploitEPSS 0%bplugins · html5 video playerSep 11, 2024