Executive brief
H5P is a popular WordPress plugin used to create and share interactive HTML5 content like quizzes, videos, and presentations. A security flaw in versions 1.17.6 and earlier allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could steal session information, redirect users to malicious sites, or deface the website.
Technical details
The H5P plugin for WordPress (versions <= 1.17.6) contains a reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a specially crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized actions on behalf of the user. The issue is resolved in version 1.17.7.
Affected products
- H5P H5P <= 1.17.6
Timeline
- 2026-06-05: other: Vulnerability reported by researcher Koutrouss Naddara
- 2026-06-18: advisory: Initial advisory published by Patchstack
- 2026-06-25: disclosed: CVE published to NVD
- 2026-06-25: patched: Patch confirmed available in version 1.17.7