CVE-2024-2428

CVE-2024-2428: The Ultimate Video Player For WordPress < 2.2.3 - Contributor+ Stored XSS

Vendor Unknown
Product The Ultimate Video Player For WordPress
Published April 10, 2024
Last update October 30, 2024

CVSS base score

What the vulnerability does

01Description

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks

Key dates

02Disclosure timeline

April 10, 2024 CVE published
October 30, 2024 Record updated