Extension WordPress
Vulnérabilités HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player
Cette page rassemble les failles publiées pour HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player
7 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.2.27
2.5.1
30/04/2026
HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 – 2.5.1 – Unauthenticated Server-Side Request Forgery
The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes…
2.4.0-2.5.1
2.5.2
18/12/2025
Html5 Audio Player <= 2.2.28 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Html5 Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-2.2.28
2.3.0
16/04/2025
Html5 Audio Player <= 2.2.23 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Html5 Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-2.2.23
2.2.24
28/06/2024
HTML5 Audio Player- Best WordPress Audio Player Plugin <= 2.2.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping…
*-2.2.19
2.2.22
09/05/2024
Html5 Audio Player <= 2.1.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Html5 Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.1.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.1.11
2.1.12
12/01/2023
Html5 Audio Player <= 2.1.2 – Contributor+ Stored Cross-Site Scripting
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them…
*-2.1.2
2.1.3
20/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.