Executive brief
The Flash & HTML5 Video plugin for WordPress, which allows site owners to embed video players, contains a security flaw that permits unauthorized access. An unauthenticated attacker could exploit this to perform actions or access information that should be restricted to administrators. This could lead to unauthorized changes to video content or exposure of internal site configurations.
Technical details
A broken access control vulnerability exists in the bPlugins Flash & HTML5 Video plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. An unauthenticated remote attacker can exploit this flaw to execute actions that should require higher privileges. The vulnerability is present in versions up to 2.11.0 and was addressed in version 2.11.1. The CVSS 3.1 vector indicates a network-based attack with low complexity and no user interaction required, resulting in a limited impact on confidentiality.
Affected products
- bPlugins Flash & HTML5 Video <= 2.11.0
Timeline
- 2026-01-26: disclosed: Reported by Nabil Irawan
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Fixed in version 2.11.1